216.73.216.6

Multiplatform Cryptomining Campaign Uses Fake Error Pages to Hide Payload

· Published 24/07/2025 08:26 · Modified 24/07/2025 09:34

Export JSON

Essential information

Published
24/07/2025 08:26
Modified
24/07/2025 09:34
Tags
2025-07-24 CVE-2025-24813 compromised-servers crypto-scam cryptomining fake-404-pages multiplatform persistence postgresql process-masquerading soco404
Related entities
1 malware, 2 others

Description

A new iteration of a broad campaign, dubbed , has been identified. The attackers exploit vulnerabilities in cloud environments, particularly targeting misconfigurations, to deploy cryptominers on both Linux and Windows systems. They use process masquerading, achieve via cron jobs and shell initialization files, and rely on compromised legitimate servers for malware hosting. The malware communicates via local sockets and embeds payloads in fake 404 HTML pages on Google Sites. The campaign is part of a larger infrastructure, demonstrating a versatile and opportunistic operation. The attackers use multiple ingress tools and target various entry points, showing a flexible approach to maximize reach and across diverse targets.

External references