Close Menu
Invest Intellect
    Facebook X (Twitter) Instagram
    Invest Intellect
    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Commodities
    • Cryptocurrency
    • Fintech
    • Investments
    • Precious Metal
    • Property
    • Stock Market
    Invest Intellect
    Home»Cryptocurrency»New Malware Hidden Within PostgreSQL Process Deploys Cryptocurrency Miners
    Cryptocurrency

    New Malware Hidden Within PostgreSQL Process Deploys Cryptocurrency Miners

    August 22, 20243 Mins Read


    New Malware Hidden Within PostgreSQL Process Deploys Cryptocurrency Miners

    A successful brute-force attack on a PostgreSQL database exploited a feature that allowed command execution, where the attacker created a superuser role, dropped files to eliminate competition and gain persistence, and ultimately deployed cryptocurrency miners. 

    The attack demonstrates the severe consequences of weak passwords and the potential for unauthorized access to a database to lead to significant security breaches.


    EHA
    Attack flow in PG_MEM

    An attacker successfully breached the system through a brute-force attack on the PostgreSQL database. After gaining access, they created a new superuser account with elevated privileges to maintain persistence.

    Free Webinar on Detecting & Blocking Supply Chain Attack -> Book your Spot

    They then stripped the initial compromised user of superuser rights to limit potential damage from future attacks.

    To gather information about the system, the attacker executed commands to locate the authentication configuration file, determine the PostgreSQL server version, and run system commands like `uname` and `whoami`. 

    The compilation of commands aimed at   the system

    The threat actor leverages a temporary table to execute shell commands and store the output by establishing a TCP connection to a remote server to download two malicious payloads, pg_core and pg_mem. 

    The first payload, pg_core, is a cryptominer that mines cryptocurrency, while the second payload, pg_mem, is a dropper that deploys the XMRIG cryptominer, memory. 

    Both payloads are designed to evade detection by removing logs, killing competing malware processes, and creating persistence through cron jobs. The threat actor also modifies the pg_hba configuration file to allow unauthorized connections.

    Mining cryptocurrency data

    A recent Shodan search revealed over 800,000 publicly accessible PostgreSQL databases on the internet, highlighting a significant security risk and making them vulnerable to brute-force attacks and potential exploitation. 

    This discovery underscores the urgent need for organizations to implement robust security measures to protect their database servers from unauthorized access.

    The attackers exploited a vulnerability in the Postgres database to gain initial access to the target system, which aligns with the T1190 technique, which involves exploiting public-facing applications to compromise systems. 

    According to AquaSec, by leveraging this vulnerability, the attackers were able to bypass security measures and establish a foothold within the target environment.

    component of the attack

    The attacker initiates a targeted attack against a PostgreSQL database server by exploiting a vulnerability in the database to execute shell commands, create a new user account with elevated privileges, and manipulate existing user roles. 

    To maintain persistence, they schedule a task to run a malicious script and delete evidence of their activity, and then leverage the elevated privileges to execute commands as a superuser. 

    By guessing the database credentials, they gain unauthorized access by collecting sensitive data, and the attacker downloads malicious files from a remote server and uses web protocols to establish communication, ultimately hijacking system resources for cryptocurrency mining.

    Are you from SOC and DFIR Teams? Analyse Malware Incidents & get live Access with ANY.RUN -> Get 14 Days Free Acces



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Court acquits defendants in cryptocurrency mining case

    Cryptocurrency

    Top 5 Cloud Mining Platforms for Cryptocurrency in 2026 – Why HashBitcoin Stands Out

    Cryptocurrency

    Better Cryptocurrency to Buy Now and Hold for 10 Years: XRP vs. Bitcoin

    Cryptocurrency

    Coinbase Faces Prospect for a Challenging 2026 as Cryptocurrency Prices Fall

    Cryptocurrency

    Poland to push ahead with cryptocurrency regulation despite presidential veto: minister

    Cryptocurrency

    Understanding Merkle Roots in Cryptocurrency: Basics and Function

    Cryptocurrency
    Leave A Reply Cancel Reply

    Top Picks
    Commodities

    Honouring 55 winners of the 3rd edition of the Sheikh Mansour bin Zayed Agricultural Excellence Award

    Cryptocurrency

    Tiny Company With China Ties Announces Big Purchase of Trump Cryptocurrency

    Investments

    Peter Crouch a marqué plus de 2025 buts à Anfield que Darwin Nunez et Diogo Jota alors que les fans demandent ‘Ramener le retour’ ‘

    Editors Picks

    Bitcoin has surrendered the rally. Why it didn’t bounce after a whale unloaded the cryptocurrency.

    August 26, 2025

    How Did CenterPoint Energy, Inc.’s (NYSE:CNP) 10% ROE Fare Against The Industry?

    October 15, 2024

    Midcounties Co-op unveils online investment management portal

    July 21, 2025

    Britain’s most active housing markets revealed

    September 10, 2025
    What's Hot

    How to think about technology investing in the current climate

    September 16, 2025

    Art Investment Strategies: How to Capitalize on the Buyer’s Art Market

    August 16, 2024

    Vosges. L’écoparc de Chavelot, un eldorado industriel à 2 milliards d’euros ?

    May 6, 2025
    Our Picks

    Thomas Faure repart à l’assaut d’une ceinture EBU silver

    April 18, 2025

    Romanian fintech Instant Factoring secures EUR 30 mln financing structure to support SMEs

    November 5, 2025

    NASDAQ 100 Slides 1.9% as Tech Stocks Weigh on Wall Street

    December 12, 2025
    Weekly Top

    How will silver price fare in 2026?

    February 16, 2026

    Premium Bonds – Three winners scoop £50,000 in County Durham

    February 16, 2026

    Can data center deal power 2026? By Investing.com

    February 16, 2026
    Editor's Pick

    Will BRICS Adopt Putin’s Ambitious Alternative Payment System?

    October 25, 2024

    Dow wavers, S&P 500, Nasdaq rise in countdown to Trump’s tariff reveal

    April 1, 2025

    C’est l’un des jeux préférés du créateur de Metal Gear et Death Stranding, et il est gratuit avec le Nintendo Switch Online

    May 4, 2025
    © 2026 Invest Intellect
    • Contact us
    • Privacy Policy
    • Terms and Conditions

    Type above and press Enter to search. Press Esc to cancel.