Close Menu
Invest Intellect
    Facebook X (Twitter) Instagram
    Invest Intellect
    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Commodities
    • Cryptocurrency
    • Fintech
    • Investments
    • Precious Metal
    • Property
    • Stock Market
    Invest Intellect
    Home»Cryptocurrency»New Malware Hidden Within PostgreSQL Process Deploys Cryptocurrency Miners
    Cryptocurrency

    New Malware Hidden Within PostgreSQL Process Deploys Cryptocurrency Miners

    August 22, 20243 Mins Read


    New Malware Hidden Within PostgreSQL Process Deploys Cryptocurrency Miners

    A successful brute-force attack on a PostgreSQL database exploited a feature that allowed command execution, where the attacker created a superuser role, dropped files to eliminate competition and gain persistence, and ultimately deployed cryptocurrency miners. 

    The attack demonstrates the severe consequences of weak passwords and the potential for unauthorized access to a database to lead to significant security breaches.


    EHA
    Attack flow in PG_MEM

    An attacker successfully breached the system through a brute-force attack on the PostgreSQL database. After gaining access, they created a new superuser account with elevated privileges to maintain persistence.

    Free Webinar on Detecting & Blocking Supply Chain Attack -> Book your Spot

    They then stripped the initial compromised user of superuser rights to limit potential damage from future attacks.

    To gather information about the system, the attacker executed commands to locate the authentication configuration file, determine the PostgreSQL server version, and run system commands like `uname` and `whoami`. 

    The compilation of commands aimed at   the system

    The threat actor leverages a temporary table to execute shell commands and store the output by establishing a TCP connection to a remote server to download two malicious payloads, pg_core and pg_mem. 

    The first payload, pg_core, is a cryptominer that mines cryptocurrency, while the second payload, pg_mem, is a dropper that deploys the XMRIG cryptominer, memory. 

    Both payloads are designed to evade detection by removing logs, killing competing malware processes, and creating persistence through cron jobs. The threat actor also modifies the pg_hba configuration file to allow unauthorized connections.

    Mining cryptocurrency data

    A recent Shodan search revealed over 800,000 publicly accessible PostgreSQL databases on the internet, highlighting a significant security risk and making them vulnerable to brute-force attacks and potential exploitation. 

    This discovery underscores the urgent need for organizations to implement robust security measures to protect their database servers from unauthorized access.

    The attackers exploited a vulnerability in the Postgres database to gain initial access to the target system, which aligns with the T1190 technique, which involves exploiting public-facing applications to compromise systems. 

    According to AquaSec, by leveraging this vulnerability, the attackers were able to bypass security measures and establish a foothold within the target environment.

    component of the attack

    The attacker initiates a targeted attack against a PostgreSQL database server by exploiting a vulnerability in the database to execute shell commands, create a new user account with elevated privileges, and manipulate existing user roles. 

    To maintain persistence, they schedule a task to run a malicious script and delete evidence of their activity, and then leverage the elevated privileges to execute commands as a superuser. 

    By guessing the database credentials, they gain unauthorized access by collecting sensitive data, and the attacker downloads malicious files from a remote server and uses web protocols to establish communication, ultimately hijacking system resources for cryptocurrency mining.

    Are you from SOC and DFIR Teams? Analyse Malware Incidents & get live Access with ANY.RUN -> Get 14 Days Free Acces



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Central Bank Digital Currency (CBDC) – Global Officials Look at New Era of Digital Finance

    Cryptocurrency

    Cryptocurrency News Live: Bitcoin, Ethereum, Solana, memecoin prices today; trading, m-cap updates

    Cryptocurrency

    Africa, Caribbean consider developing digital currency to enhance trade

    Cryptocurrency

    Cryptocurrency Live News & Updates : Powell Remains Silent on Future Fed Role

    Cryptocurrency

    WinnerMining: Are cryptocurrency fluctuations making people panic? No, it’s the business opportunities of cloud mining.

    Cryptocurrency

    A new cloud mining solution is launched globally, redefining the passive income model of cryptocurrency

    Cryptocurrency
    Leave A Reply Cancel Reply

    Top Picks
    Investments

    La perte attribuable de Salt Investments s’aggrave au cours du troisième trimestre fiscal ; les actions augmentent de 33%. -Le 17 février 2025 à 07:28

    Commodities

    Axian Energy donne le coup d’envoi pour la construction de la centrale solaire NEA Kolda

    Commodities

    Major automakers fall short on transparency in battery metal sourcing, Amnesty says

    Editors Picks

    Cryptocurrency Prices on August 22: Bitcoin rises above $60,700 on US rate-cut bets; Ethereum gains

    August 22, 2024

    Patrick Mameli – Pestilence ‘The Dutch Metal Forefathers’ Maiden Aussie Tour’

    October 30, 2024

    U.S. Department of Energy awards Duke Energy project $57 million in cost-share funding to enhance North Carolina’s energy grid | Duke Energy

    August 6, 2024

    Are You Looking for a High-Growth Dividend Stock?

    June 9, 2025
    What's Hot

    Next Cryptocurrency to Explode, 17 May — Sui, Core, UPCX

    May 17, 2025

    JPMorgan Targets Digital Payments with New JPMD Trademark Filing

    June 17, 2025

    Stripe Acquires Privy to Accelerate the Future of Digital Ownership and Crypto Infrastructure

    June 12, 2025
    Our Picks

    How Heriot became the hottest band in UK underground metal

    October 23, 2024

    UK property market sees green shoots as buyers anticipate rate cut, lower mortgage rates

    July 22, 2024

    Mubawab affirme son virage technologique sous un nouvel actionnariat

    May 13, 2025
    Weekly Top

    Cryptocurrency News Live: Bitcoin, Ethereum, Solana, memecoin prices today; trading, m-cap updates

    July 1, 2025

    DL Holdings signe un protocole d’accord avec Asseto Fintech pour explorer la tokenisation d’actifs réels ; l’action grimpe de 11 %

    July 1, 2025

    Dividend Stock: SmallCap Automaker Fixes Record Date For 180% Final Dividend | Markets News

    July 1, 2025
    Editor's Pick

    What will millennial investors pick?- The Week

    October 26, 2024

    Dalqan Real Estate : Bénéfice du 4ème trimestre 532.601 Dinars -Le 02 mars 2025 à 11:59

    March 2, 2025

    Gold is an uncertain certainty amid Trump tariff turmoil

    April 14, 2025
    © 2025 Invest Intellect
    • Contact us
    • Privacy Policy
    • Terms and Conditions

    Type above and press Enter to search. Press Esc to cancel.