Tuesday, March 4, 2025
HomeCryptocurrency hackHackers Abused Oracle WebLogic Server for Mining Cryptocurrencies

Hackers Abused Oracle WebLogic Server for Mining Cryptocurrencies

Published on

SIEM as a Service

Follow Us on Google News

There is a rapid growth in cryptocurrency attacks from the mid of 2017, mining cryptocurrency requires more computing power, which requires significant amounts of energy. Attackers abuses Oracle WebLogic Server vulnerability to deliver Monero Miner Payloads.

As long as your server has RCE vulnerability attackers take an advantage of it and include malicious scripts. The cryptocurrency attacks not only compromise the system, it consumes all the system resources.

Attackers use already patched vulnerability CVE-2017-10271 that allows remote code execution to deliver cryptocurrency miners payload. Security researchers from TrendMicro spotted the abuse of vulnerability by the cybercriminal to mine Monero.

Once the Coinminer_MALXMR[.]JL-PS is executed it downloads three files, one autostart component and two autostart components one for Windows 64-bit & and another for 32-bit.Trend Micro detected it as Coinminer_TOOLXMR[.]JL-WIN64 and Coinminer_MALXMR[.]JLT-WIN32.
Oracle WebLogic Server
Payload Execution

Based on the Windows operating system architecture it decides which miner to run, either 64-bit variant or 32-bit variant of an XMRig Monero miner.

Last week attackers targetted Apache CouchDB patched vulnerabilities CVE-2017-12635 (Apache CouchDB JSON Remote Privilege Escalation Vulnerability) and CVE-2017-12636 (Apache CouchDB _config Command Execution) to mine Cryptocurrency.

It is not the first Oracle Weblogic were Exploited, last month attackers used the same vulnerability to install and run crypto miners. Following are the version affected with the vulnerability 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0.

Hackers taking each and every opportunity for mining cryptocurrencies, even they inserted Cryptocurrency Mining Script with the embedded videos in word documents.

And if the user plays the video the Embedded script will be executed and suddenly system CPU Process getting higher and can reach up to 99%.

It is recommended to update your application regularly to mitigate the threats that exploit system vulnerabilities.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Update Alert: Google Warns of Critical Android Vulnerabilities Under Exploit

Google’s March 2025 Android Security Bulletin has unveiled two critical vulnerabilities—CVE-2024-43093 and CVE-2024-50302—currently under...

BigAnt Server 0-Day Vulnerability Lets Attackers Run Malicious Code Remotely

A critical vulnerability in BigAntSoft's enterprise chat server software has exposed ~50 internet-facing systems...

Bubba AI, Inc. is Launching Comp AI to Help 100,000 Startups Get SOC 2 Compliant by 2032.

With the growing importance of security compliance for startups, more companies are seeking to...

IBM Storage Virtualize Flaws Allow Remote Code Execution

Two critical security flaws in IBM Storage Virtualize products could enable attackers to bypass...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Stablecoin Bank Hit by Cyberattack, Loses $49.5M to Hackers

The cryptocurrency sector faced one of its most significant security breaches this year as...

Biggest Crypto Hack in History – Hackers Stolen $1.46 Billion Worth Crypto From Bybit

In what has become the largest cryptocurrency theft in history, hackers infiltrated Bybit’s Ethereum...

Malicious Solana Packages Attacking Devs Abusing Slack And ImgBB For Data Theft

Malicious packages "solanacore," "solana login," and "walletcore-gen" on npmjs target Solana developers with Windows...