216.73.217.22

Cryptomining Campaign Exploiting Grid Services

· Published 30/07/2024 15:45 · Modified 30/07/2024 16:30

Export JSON

Essential information

Published
30/07/2024 15:45
Modified
30/07/2024 16:30
Tags
2024-07-30 cryptomining grid selenium threat webdriver xmrig
Related entities
14 observables, 7 techniques (mitre), 1 malware

Description

Wiz researchers discovered an ongoing campaign, dubbed 'SeleniumGreed', that exploits exposed services for . The campaign targets publicly accessible instances of , an integral component of the widely used testing framework. By leveraging features of API, the actor executes remote commands, deploys a modified miner, and employs various techniques to evade detection and maximize mining efforts.

External references