Wednesday, May 14, 2025
HomeCryptocurrency hackHackers Abused Oracle WebLogic Server for Mining Cryptocurrencies

Hackers Abused Oracle WebLogic Server for Mining Cryptocurrencies

Published on

SIEM as a Service

Follow Us on Google News

There is a rapid growth in cryptocurrency attacks from the mid of 2017, mining cryptocurrency requires more computing power, which requires significant amounts of energy. Attackers abuses Oracle WebLogic Server vulnerability to deliver Monero Miner Payloads.

As long as your server has RCE vulnerability attackers take an advantage of it and include malicious scripts. The cryptocurrency attacks not only compromise the system, it consumes all the system resources.

Attackers use already patched vulnerability CVE-2017-10271 that allows remote code execution to deliver cryptocurrency miners payload. Security researchers from TrendMicro spotted the abuse of vulnerability by the cybercriminal to mine Monero.

Once the Coinminer_MALXMR[.]JL-PS is executed it downloads three files, one autostart component and two autostart components one for Windows 64-bit & and another for 32-bit.Trend Micro detected it as Coinminer_TOOLXMR[.]JL-WIN64 and Coinminer_MALXMR[.]JLT-WIN32.
- Advertisement - Google News
Oracle WebLogic Server
Payload Execution

Based on the Windows operating system architecture it decides which miner to run, either 64-bit variant or 32-bit variant of an XMRig Monero miner.

Last week attackers targetted Apache CouchDB patched vulnerabilities CVE-2017-12635 (Apache CouchDB JSON Remote Privilege Escalation Vulnerability) and CVE-2017-12636 (Apache CouchDB _config Command Execution) to mine Cryptocurrency.

It is not the first Oracle Weblogic were Exploited, last month attackers used the same vulnerability to install and run crypto miners. Following are the version affected with the vulnerability 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0.

Hackers taking each and every opportunity for mining cryptocurrencies, even they inserted Cryptocurrency Mining Script with the embedded videos in word documents.

And if the user plays the video the Embedded script will be executed and suddenly system CPU Process getting higher and can reach up to 99%.

It is recommended to update your application regularly to mitigate the threats that exploit system vulnerabilities.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Windows Ancillary for WinSock 0-Day Vulnerability Actively Exploited to Gain Admin Access

Microsoft has confirmed active exploitation of a critical privilege escalation vulnerability in the Windows...

Earth Ammit Hackers Deploy New Tools to Target Military Drones

The threat actor group known as Earth Ammit, believed to be associated with Chinese-speaking...

New Microsoft Scripting Engine Vulnerability Exposes Systems to Remote Code Attacks

Critical zero-day vulnerability in Microsoft’s Scripting Engine (CVE-2025-30397) has been confirmed to enable remote...

Critical Microsoft Office Vulnerabilities Enable Malicious Code Execution

Microsoft has addressed three critical security flaws in its Office suite, including two vulnerabilities...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

North Korean Hacker Tries to Infiltrate Kraken Through Job Application

Leading cryptocurrency exchange Kraken has disclosed that it recently thwarted an infiltration attempt by...

Crypto Platform OKX Suspends Tool Abused by North Korean Hackers

Cryptocurrency platform OKX has announced the temporary suspension of its Decentralized Exchange (DEX) aggregator...

Authorities Seize $31 Million Linked to Crypto Exchange Hack

U.S. authorities announced the seizure of $31 million tied to the 2021 Uranium Finance...