#crypto-miner — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #crypto-miner, aggregated by home.social.
-
#HolaBrowser for #Windows compromised to deliver #cryptominer
-
#HolaBrowser for #Windows compromised to deliver #cryptominer
-
Hola Browser Compromised to Deliver Cryptominer in Supply Chain Attack
Hola's CEO, Avi Raz Cohen, assured users that the company has taken swift action to prevent future breaches, rebuilding its distribution pipeline and implementing robust security measures. The move comes after a supply chain attack compromised the Hola Browser, secretly delivering a cryptominer to unsuspecting users.
#SupplyChainAttack #Cryptominer #HolaBrowser #MalwareOperations #EmergingThreats
-
Watch out as new .NET AOT malware hides its code as a black box, making detection far harder while delivering Rhadamanthys infostealer and crypto miner.
Read: https://hackread.com/net-aot-malware-code-black-box-evade-detection/
-
Watch out as new .NET AOT malware hides its code as a black box, making detection far harder while delivering Rhadamanthys infostealer and crypto miner.
Read: https://hackread.com/net-aot-malware-code-black-box-evade-detection/
-
I had a chance last week to chat with Benjamin Read of #Wiz. Last month, Read and other members of his team published a deep dive into the #React2Shell
(CVE-2025-55182) vulnerability, and I was curious to see what has been hitting my honeypot, so I took a closer look.This is doing some weird stuff, friends.
As is normally the case with exploits targeting internet-facing devices, once the exploit becomes known, it ends up in the automated scanners used by threat actors and security researchers. What I've seen over the past week is a combination of both.
In just a few hours of operation, I identified a small number of source IP addresses exploiting React2Shell by pointing the vulnerable system at URLs hosting BASH scripts. These scripts are really familiar to anyone who routinely looks at honeypot data - they contain a series of commands that pull down and execute malicious payloads.
And as I've seen in the past, some of these payloads use racially inflammatory language in their malware. It's weird and gross, but unfortunately, really common.
But while most of these payloads were "the usual suspects" - remote shells, cryptocurrency miners - there was one payload that stuck out.
It's an exploit file, based on this proof-of-concept [https://github.com/iotwar/FIVEM-POC/blob/main/fivem-poc.py] designed to DDoS a modded server running "FiveM," a popular version of the game Grand Theft Auto V.
Let that one sink in: among the earliest adopters of a brand new exploit are...people trying to mess with other people's online game servers.
I've long said that exploits like these are the canaries in the datacenter coal mine. After all, if an attacker can force your server to run a cryptominer (or a game DDoS tool), they can force it to run far more malicious code.
I guess someone, or a group of someones, just want to ruin everyone's good time, no matter how or what form that takes. And they'll do it in the most offensive way possible.
Anyway, patch your servers, please, if only to stick it to these people who want to be the reason we can't have nice things.
#PoC #exploit #CVE_2025_55182 #DDoS #FiveM #REACT #Bash #cryptominer #malware
-
I had a chance last week to chat with Benjamin Read of #Wiz. Last month, Read and other members of his team published a deep dive into the #React2Shell
(CVE-2025-55182) vulnerability, and I was curious to see what has been hitting my honeypot, so I took a closer look.This is doing some weird stuff, friends.
As is normally the case with exploits targeting internet-facing devices, once the exploit becomes known, it ends up in the automated scanners used by threat actors and security researchers. What I've seen over the past week is a combination of both.
In just a few hours of operation, I identified a small number of source IP addresses exploiting React2Shell by pointing the vulnerable system at URLs hosting BASH scripts. These scripts are really familiar to anyone who routinely looks at honeypot data - they contain a series of commands that pull down and execute malicious payloads.
And as I've seen in the past, some of these payloads use racially inflammatory language in their malware. It's weird and gross, but unfortunately, really common.
But while most of these payloads were "the usual suspects" - remote shells, cryptocurrency miners - there was one payload that stuck out.
It's an exploit file, based on this proof-of-concept [https://github.com/iotwar/FIVEM-POC/blob/main/fivem-poc.py] designed to DDoS a modded server running "FiveM," a popular version of the game Grand Theft Auto V.
Let that one sink in: among the earliest adopters of a brand new exploit are...people trying to mess with other people's online game servers.
I've long said that exploits like these are the canaries in the datacenter coal mine. After all, if an attacker can force your server to run a cryptominer (or a game DDoS tool), they can force it to run far more malicious code.
I guess someone, or a group of someones, just want to ruin everyone's good time, no matter how or what form that takes. And they'll do it in the most offensive way possible.
Anyway, patch your servers, please, if only to stick it to these people who want to be the reason we can't have nice things.
#PoC #exploit #CVE_2025_55182 #DDoS #FiveM #REACT #Bash #cryptominer #malware
-
Dormant Bitcoin Whale With $442M Awakens for First Time in 14 Years Amid Quantum Fears - 14-year-old wallet moves $16.6M in BTC as analyst weigh security concerns and shifting on... - https://www.coindesk.com/markets/2025/10/24/dormant-bitcoin-whale-with-usd442m-awakens-for-first-time-in-14-years-amid-quantum-fears #cryptominer #markets #bitcoin #news
-
Dormant Bitcoin Whale With $442M Awakens for First Time in 14 Years Amid Quantum Fears - 14-year-old wallet moves $16.6M in BTC as analyst weigh security concerns and shifting on... - https://www.coindesk.com/markets/2025/10/24/dormant-bitcoin-whale-with-usd442m-awakens-for-first-time-in-14-years-amid-quantum-fears #cryptominer #markets #bitcoin #news
-
Crypto Miner TeraWulf to Raise $3B in Google-Backed Debt Deal to Expand Data Centers - Crypto mining firm TeraWulf (WULF) is planning to raise $3 billion in debt to expand its ... - https://www.coindesk.com/business/2025/09/27/crypto-miner-terawulf-to-raise-usd3b-in-google-backed-debt-deal-to-expand-data-centers #artificialintelligence #cryptominer #datacenters #finance #google #news
-
Crypto Miner TeraWulf to Raise $3B in Google-Backed Debt Deal to Expand Data Centers - Crypto mining firm TeraWulf (WULF) is planning to raise $3 billion in debt to expand its ... - https://www.coindesk.com/business/2025/09/27/crypto-miner-terawulf-to-raise-usd3b-in-google-backed-debt-deal-to-expand-data-centers #artificialintelligence #cryptominer #datacenters #finance #google #news
-
New Malware Uses Windows Character Map for Cryptomining https://hackread.com/new-malware-uses-windows-character-map-cryptomining/ #Cryptocurrency #Cryptojacking #Cryptomining #Cryptominer #CyberAttack #PowerShell #Darktrace #Security #Malware #NBMiner #Windows #Autolt
-
New Malware Uses Windows Character Map for Cryptomining https://hackread.com/new-malware-uses-windows-character-map-cryptomining/ #Cryptocurrency #Cryptojacking #Cryptomining #Cryptominer #CyberAttack #PowerShell #Darktrace #Security #Malware #NBMiner #Windows #Autolt
-
New Malware Uses Windows Character Map for Cryptomining – Source:hackread.com https://ciso2ciso.com/new-malware-uses-windows-character-map-for-cryptomining-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #Cryptocurrency #Cryptojacking #Cryptomining #Cryptominer #CyberAttack #PowerShell #Darktrace #Hackread #security #malware #NBMiner #Windows #Autolt
-
New Malware Uses Windows Character Map for Cryptomining – Source:hackread.com https://ciso2ciso.com/new-malware-uses-windows-character-map-for-cryptomining-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #Cryptocurrency #Cryptojacking #Cryptomining #Cryptominer #CyberAttack #PowerShell #Darktrace #Hackread #security #malware #NBMiner #Windows #Autolt
-
Years Long Linux Cryptominer Spotted Using Legit Sites to Spread Malware https://hackread.com/linux-cryptominer-using-legit-sites-to-spread-malware/ #Cybersecurity #Vulnerability #Cryptominer #VulnCheck #Security #Linuxsys #Malware #Windows #Monero #XMR
-
Years Long Linux Cryptominer Spotted Using Legit Sites to Spread Malware https://hackread.com/linux-cryptominer-using-legit-sites-to-spread-malware/ #Cybersecurity #Vulnerability #Cryptominer #VulnCheck #Security #Linuxsys #Malware #Windows #Monero #XMR
-
Years Long Linux Cryptominer Spotted Using Legit Sites to Spread Malware – Source:hackread.com https://ciso2ciso.com/years-long-linux-cryptominer-spotted-using-legit-sites-to-spread-malware-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #cybersecurity #Vulnerability #Cryptominer #VulnCheck #Hackread #Linuxsys #security #malware #Windows #Monero #XMR
-
Years Long Linux Cryptominer Spotted Using Legit Sites to Spread Malware – Source:hackread.com https://ciso2ciso.com/years-long-linux-cryptominer-spotted-using-legit-sites-to-spread-malware-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #cybersecurity #Vulnerability #Cryptominer #VulnCheck #Hackread #Linuxsys #security #malware #Windows #Monero #XMR
-
A Linux cryptominer has been quietly spreading malware for years by hijacking legit websites with SSL certs.
🔗 https://hackread.com/linux-cryptominer-using-legit-sites-to-spread-malware/
-
A Linux cryptominer has been quietly spreading malware for years by hijacking legit websites with SSL certs.
🔗 https://hackread.com/linux-cryptominer-using-legit-sites-to-spread-malware/
-
Finally completed my rebuild of my #Grafana #prometheus #vps stack.
The old one was hosed in a 3 month battle with a #cryptominer
It was #docker but they kept fucking the Prometheus container.I rebuild everything from scratch. The panels are integrated into a single JSON file, rather than in libraries.
The stack is now #podman. Rootless execution.
But I couldn't get it to get #cadvisor to feed it.
So I got a dodgy scraper script.
But even with nice, it loads the low tier VPS to 14% -
Every #appliance that's job is to get hot should be a #cryptoMiner or a #heatPump
#electronics #technology #bitcoin #cryptocurrency #crypto #appliances #home
-
Every #appliance that's job is to get hot should be a #cryptoMiner or a #heatPump
#electronics #technology #bitcoin #cryptocurrency #crypto #appliances #home
-
Tether Raises Bitdeer Stake to 21%: SEC Filing - Tether, the issuer of the USDT stablecoin, increased its holdings in bitcoin (BTC) miner ... - https://www.coindesk.com/markets/2025/03/18/tether-increases-holdings-in-bitdeer-to-20-sec-filing #mergersandacquisitions #cryptominer #markets #bitdeer #tether
-
Tether Raises Bitdeer Stake to 21%: SEC Filing - Tether, the issuer of the USDT stablecoin, increased its holdings in bitcoin (BTC) miner ... - https://www.coindesk.com/markets/2025/03/18/tether-increases-holdings-in-bitdeer-to-20-sec-filing #mergersandacquisitions #cryptominer #markets #bitdeer #tether
-
Cybercriminals are blackmailing YouTubers with fake copyright claims! 😱 They're threatening creators into distributing malware disguised as download links. A trojanized program installs a cryptominer. ⚠️ Be careful what you download! More info: https://www.techradar.com/pro/security/youtubers-targeted-by-blackmail-campaign-to-promote-malware-on-their-channels #cybersecurity #malware #youtube #cryptominer #newz
-
Cybercriminals are blackmailing YouTubers with fake copyright claims! 😱 They're threatening creators into distributing malware disguised as download links. A trojanized program installs a cryptominer. ⚠️ Be careful what you download! More info: https://www.techradar.com/pro/security/youtubers-targeted-by-blackmail-campaign-to-promote-malware-on-their-channels #cybersecurity #malware #youtube #cryptominer #newz
-
Mass exploitation campaign hit 4,000+ ISP networks to deploy info stealers and crypto miners – Source: securityaffairs.com https://ciso2ciso.com/mass-exploitation-campaign-hit-4000-isp-networks-to-deploy-info-stealers-and-crypto-miners-source-securityaffairs-com/ #rssfeedpostgeneratorecho #ITInformationSecurity #SecurityAffairscom #CyberSecurityNews #PierluigiPaganini #SecurityAffairs #SecurityAffairs #BreakingNews #SecurityNews #cryptominer #hackingnews #CyberCrime #Cybercrime #hacking #Malware
-
Mass exploitation campaign hit 4,000+ ISP networks to deploy info stealers and crypto miners – Source: securityaffairs.com https://ciso2ciso.com/mass-exploitation-campaign-hit-4000-isp-networks-to-deploy-info-stealers-and-crypto-miners-source-securityaffairs-com/ #rssfeedpostgeneratorecho #ITInformationSecurity #SecurityAffairscom #CyberSecurityNews #PierluigiPaganini #SecurityAffairs #SecurityAffairs #BreakingNews #SecurityNews #cryptominer #hackingnews #CyberCrime #Cybercrime #hacking #Malware
-
CVE-2021-41773 oraz CVE-2021-42013 kończące się kopaniem krypto przez RedTail ( https://nfsec.pl/ai/6597 ) #cryptominer #botnet #redtail #linux #security #twittermigration
-
CVE-2021-41773 oraz CVE-2021-42013 kończące się kopaniem krypto przez RedTail ( https://nfsec.pl/ai/6597 ) #cryptominer #botnet #redtail #linux #security #twittermigration
-
Hackers Use CVE-2024-50603 to Deploy Backdoor on Aviatrix Controllers – Source:hackread.com https://ciso2ciso.com/hackers-use-cve-2024-50603-to-deploy-backdoor-on-aviatrix-controllers-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #cybersecurity #Vulnerability #Cryptominer #Aviatrix #backdoor #Hackread #security #RCE
-
Hackers Use CVE-2024-50603 to Deploy Backdoor on Aviatrix Controllers – Source:hackread.com https://ciso2ciso.com/hackers-use-cve-2024-50603-to-deploy-backdoor-on-aviatrix-controllers-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #cybersecurity #Vulnerability #Cryptominer #Aviatrix #backdoor #Hackread #security #RCE
-
Hackers Use CVE-2024-50603 to Deploy Backdoor on Aviatrix Controllers https://hackread.com/hackers-cve-2024-50603-aviatrix-controllers-backdoor/ #Cybersecurity #Vulnerability #Cryptominer #Security #Aviatrix #backdoor #RCE
-
Hackers Use CVE-2024-50603 to Deploy Backdoor on Aviatrix Controllers https://hackread.com/hackers-cve-2024-50603-aviatrix-controllers-backdoor/ #Cybersecurity #Vulnerability #Cryptominer #Security #Aviatrix #backdoor #RCE
-
Fake Job Offers from CrowdStrike Used by Cybercriminals to Distribute Cryptominer - https://www.redpacketsecurity.com/cybercriminals-use-fake-crowdstrike-job-offers-to-distribute-cryptominer/
-
Fake Job Offers from CrowdStrike Used by Cybercriminals to Distribute Cryptominer - https://www.redpacketsecurity.com/cybercriminals-use-fake-crowdstrike-job-offers-to-distribute-cryptominer/
-
Fake CrowdStrike Recruiters Distribute Malware Via Phishing Emails – Source:hackread.com https://ciso2ciso.com/fake-crowdstrike-recruiters-distribute-malware-via-phishing-emails-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #cybersecurity #PhishingScam #CrowdStrike #Cryptominer #Hackread #Phishing #security #malware #Fraud #Scam
-
Fake CrowdStrike Recruiters Distribute Malware Via Phishing Emails – Source:hackread.com https://ciso2ciso.com/fake-crowdstrike-recruiters-distribute-malware-via-phishing-emails-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #cybersecurity #PhishingScam #CrowdStrike #Cryptominer #Hackread #Phishing #security #malware #Fraud #Scam
-
Fake CrowdStrike Recruiters Distribute Malware Via Phishing Emails https://hackread.com/fake-crowdstrike-recruiters-malware-phishing-emails/ #Cybersecurity #PhishingScam #CrowdStrike #Cryptominer #Security #Phishing #Malware #Fraud #Scam
-
Fake CrowdStrike Recruiters Distribute Malware Via Phishing Emails https://hackread.com/fake-crowdstrike-recruiters-malware-phishing-emails/ #Cybersecurity #PhishingScam #CrowdStrike #Cryptominer #Security #Phishing #Malware #Fraud #Scam
-
Phishers abuse CrowdStrike brand targeting job seekers with cryptominer – Source: securityaffairs.com https://ciso2ciso.com/phishers-abuse-crowdstrike-brand-targeting-job-seekers-with-cryptominer-source-securityaffairs-com/ #rssfeedpostgeneratorecho #informationsecuritynews #ITInformationSecurity #SecurityAffairscom #CyberSecurityNews #PierluigiPaganini #SecurityAffairs #SecurityAffairs #BreakingNews #SecurityNews #CrowdStrike #cryptominer #hackingnews #CyberCrime #Phishing #hacking #Malware
-
Phishers abuse CrowdStrike brand targeting job seekers with cryptominer – Source: securityaffairs.com https://ciso2ciso.com/phishers-abuse-crowdstrike-brand-targeting-job-seekers-with-cryptominer-source-securityaffairs-com/ #rssfeedpostgeneratorecho #informationsecuritynews #ITInformationSecurity #SecurityAffairscom #CyberSecurityNews #PierluigiPaganini #SecurityAffairs #SecurityAffairs #BreakingNews #SecurityNews #CrowdStrike #cryptominer #hackingnews #CyberCrime #Phishing #hacking #Malware
-
Ultralytics AI Library with 60M Downloads Compromised for Cryptomining – Source:hackread.com https://ciso2ciso.com/ultralytics-ai-library-with-60m-downloads-compromised-for-cryptomining-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #Cryptocurrency #UltralyticsAI #Cryptominer #Hackread #security #malware #Crypto #Python #PyPI
-
Ultralytics AI Library with 60M Downloads Compromised for Cryptomining – Source:hackread.com https://ciso2ciso.com/ultralytics-ai-library-with-60m-downloads-compromised-for-cryptomining-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #Cryptocurrency #UltralyticsAI #Cryptominer #Hackread #security #malware #Crypto #Python #PyPI
-
Ultralytics AI Library with 60M Downloads Compromised for Cryptomining https://hackread.com/ultralytics-ai-library-compromised-for-cryptomining/ #Cryptocurrency #UltralyticsAI #Cryptominer #Security #Malware #Crypto #Python #PyPI
-
Ultralytics AI Library with 60M Downloads Compromised for Cryptomining https://hackread.com/ultralytics-ai-library-compromised-for-cryptomining/ #Cryptocurrency #UltralyticsAI #Cryptominer #Security #Malware #Crypto #Python #PyPI
-
While crypto is dumb, this take on crypto is also dumb.
Arkansas officials halt cryptomine near LR Airbase due to national security concerns
https://katv.com/news/local/arkansas-officials-halt-cryptomine-near-lr-airbase-due-to-national-security-concerns-state-senator-ricky-hill-lonoke-county-judge-doug-erwin-cabot-mayor-ken-kincade-interstate-holdings-arkansas-blockchain-council-benjamin-smith-steven-landers-jr-lrafb
#crypto #cryptocurrency #cryptocult #cryptominer #cryptominers #arkansas #littlerock #ArkansasPolitics -
While crypto is dumb, this take on crypto is also dumb.
Arkansas officials halt cryptomine near LR Airbase due to national security concerns
https://katv.com/news/local/arkansas-officials-halt-cryptomine-near-lr-airbase-due-to-national-security-concerns-state-senator-ricky-hill-lonoke-county-judge-doug-erwin-cabot-mayor-ken-kincade-interstate-holdings-arkansas-blockchain-council-benjamin-smith-steven-landers-jr-lrafb
#crypto #cryptocurrency #cryptocult #cryptominer #cryptominers #arkansas #littlerock #ArkansasPolitics -
Crypto swiping malware infects 28K users, steals just $6K: Report - A cryptojacking and stealing malware infected tens of thousands of devic... - https://cointelegraph.com/news/cryptojacking-stealing-malware-infects-28k-stole-6k-doctor-web #crypto-jacking #cryptominer #clipboard #clipper #malware