New cryptomining malware discovered

B2B Cyber ​​Security ShortNews

Share post

Security researchers have discovered a new cryptomining campaign called Lucifer that targets Apache and in particular the software libraries Hadoop and Druid, which are popular with many users.

To do this, the attackers exploit existing misconfigurations and vulnerabilities. The active campaign uses a new variant of a well-known DDoS botnet focused on vulnerable Linux systems. The malware is known as “Lucifer” and, once compromised, uses infected Apache servers to mine the cryptocurrency Monero. The cybercriminals behind Lucifer focus on the Apache libraries Hadoop and Druid, which are very popular with developers, and use existing security gaps or misconfigurations to compromise them.

Sharp increase in attacks

Team Nautilus was able to find the first attacks with Lucifer in its honeypots, which took place as early as July 2023. The team suspects that these are tests conducted by the attackers to evaluate techniques to bypass defenses and evade detection of the malware. Over the last year, security experts have observed a steady increase in attacks. In the last month alone, over 3.000 different attacks were detected.

More at AquaSecurity.com

 


About Aqua Security

Aqua Security is the largest pure cloud native security provider. Aqua gives its customers the freedom to innovate and accelerate their digital transformation. The Aqua platform provides prevention, detection, and response automation across the application lifecycle to secure the supply chain, cloud infrastructure, and ongoing workloads—regardless of where they are deployed.


 

Matching articles on the topic

Report: 40 percent more phishing worldwide

The current spam and phishing report from Kaspersky for 2023 speaks for itself: users in Germany are after ➡ Read more

BSI sets minimum standards for web browsers

The BSI has revised the minimum standard for web browsers for administration and published version 3.0. You can remember that ➡ Read more

Stealth malware targets European companies

Hackers are attacking many companies across Europe with stealth malware. ESET researchers have reported a dramatic increase in so-called AceCryptor attacks via ➡ Read more

IT security: Basis for LockBit 4.0 defused

Trend Micro, working with the UK's National Crime Agency (NCA), analyzed the unpublished version that was in development ➡ Read more

MDR and XDR via Google Workspace

Whether in a cafe, airport terminal or home office – employees work in many places. However, this development also brings challenges ➡ Read more

Test: Security software for endpoints and individual PCs

The latest test results from the AV-TEST laboratory show very good performance of 16 established protection solutions for Windows ➡ Read more

FBI: Internet Crime Report counts $12,5 billion in damage 

The FBI's Internet Crime Complaint Center (IC3) has released its 2023 Internet Crime Report, which includes information from over 880.000 ➡ Read more

HeadCrab 2.0 discovered

The HeadCrab campaign against Redis servers, which has been active since 2021, continues to successfully infect targets with the new version. The criminals' mini-blog ➡ Read more