Multiplatform Cryptomining Campaign Uses Fake Error Pages to Hide Payload
Essential information
- Published
- 24/07/2025 08:26
- Modified
- 24/07/2025 09:34
- Tags
- 2025-07-24 CVE-2025-24813 compromised-servers crypto-scam cryptomining fake-404-pages multiplatform persistence postgresql process-masquerading soco404
- Related entities
- 1 malware, 2 others
Description
A new iteration of a broad cryptomining campaign, dubbed Soco404, has been identified. The attackers exploit vulnerabilities in cloud environments, particularly targeting PostgreSQL misconfigurations, to deploy cryptominers on both Linux and Windows systems. They use process masquerading, achieve persistence via cron jobs and shell initialization files, and rely on compromised legitimate servers for malware hosting. The malware communicates via local sockets and embeds payloads in fake 404 HTML pages on Google Sites. The campaign is part of a larger crypto-scam infrastructure, demonstrating a versatile and opportunistic operation. The attackers use multiple ingress tools and target various entry points, showing a flexible approach to maximize reach and persistence across diverse targets.