216.73.217.22

Attacker Abuses Victim Resources to Reap Rewards from Titan Network

· Published 04/11/2024 12:01 · Modified 04/11/2024 12:02

Export JSON

Essential information

Published
04/11/2024 12:01
Modified
04/11/2024 12:02
Tags
2024-11-04 CVE-2023-22527 aleo-pool atlassian confluence aws cassini testnet cryptomining remote code execution ssh titan network
Related entities
1 vulnerabilities (cve), 1 observables, 9 techniques (mitre)

Description

An attacker exploited the vulnerability to achieve for via the . The malicious actor gathered system details using public IP lookup services and various commands. Multiple shell scripts were downloaded and executed to install Titan binaries and connect compromised machines to the , specifically the . This allowed the attacker to participate in the delegated proof of stake system for reward tokens. The attack also involved installing an client for additional activities. Furthermore, attempts at lateral movement through in cloud were observed, including the deployment of public keys and modification of configurations.

External references