216.73.217.22

From Automation to Exploitation: The Growing Misuse of Selenium Grid for Cryptomining and Proxyjacking

· Published 17/09/2024 11:14 · Modified 17/09/2024 11:28

Export JSON

Essential information

Published
17/09/2024 11:14
Modified
17/09/2024 11:28
Tags
2024-09-17 cryptomining gsocket iproyal pawns perfcc proxyjacking selenium grid tor traffmonetizer vulnerability exploitation
Related entities
1 vulnerabilities (cve), 18 observables, 11 techniques (mitre), 2 malware

Description

Two campaigns targeting , a popular web testing tool, have been identified. The attacks exploit misconfigured instances lacking authentication to deploy cryptominers and tools. The first campaign injects a base64 encoded Python script to download and execute a reverse shell, followed by scripts that install for and for traffic monetization. The second campaign similarly injects a script that downloads and executes an ELF binary. This binary attempts privilege escalation, connects to nodes for C2, and drops the '' cryptominer. Both campaigns highlight the risks of misconfigured instances and the need for proper authentication.

External references