Wednesday, April 23, 2025
HomeCryptocurrency hackHackers Abused Oracle WebLogic Server for Mining Cryptocurrencies

Hackers Abused Oracle WebLogic Server for Mining Cryptocurrencies

Published on

SIEM as a Service

Follow Us on Google News

There is a rapid growth in cryptocurrency attacks from the mid of 2017, mining cryptocurrency requires more computing power, which requires significant amounts of energy. Attackers abuses Oracle WebLogic Server vulnerability to deliver Monero Miner Payloads.

As long as your server has RCE vulnerability attackers take an advantage of it and include malicious scripts. The cryptocurrency attacks not only compromise the system, it consumes all the system resources.

Attackers use already patched vulnerability CVE-2017-10271 that allows remote code execution to deliver cryptocurrency miners payload. Security researchers from TrendMicro spotted the abuse of vulnerability by the cybercriminal to mine Monero.

Once the Coinminer_MALXMR[.]JL-PS is executed it downloads three files, one autostart component and two autostart components one for Windows 64-bit & and another for 32-bit.Trend Micro detected it as Coinminer_TOOLXMR[.]JL-WIN64 and Coinminer_MALXMR[.]JLT-WIN32.
- Advertisement - Google News
Oracle WebLogic Server
Payload Execution

Based on the Windows operating system architecture it decides which miner to run, either 64-bit variant or 32-bit variant of an XMRig Monero miner.

Last week attackers targetted Apache CouchDB patched vulnerabilities CVE-2017-12635 (Apache CouchDB JSON Remote Privilege Escalation Vulnerability) and CVE-2017-12636 (Apache CouchDB _config Command Execution) to mine Cryptocurrency.

It is not the first Oracle Weblogic were Exploited, last month attackers used the same vulnerability to install and run crypto miners. Following are the version affected with the vulnerability 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0.

Hackers taking each and every opportunity for mining cryptocurrencies, even they inserted Cryptocurrency Mining Script with the embedded videos in word documents.

And if the user plays the video the Embedded script will be executed and suddenly system CPU Process getting higher and can reach up to 99%.

It is recommended to update your application regularly to mitigate the threats that exploit system vulnerabilities.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

New Malware Hijacks Docker Images Using Unique Obfuscation Technique

A recently uncovered malware campaign targeting Docker, one of the most frequently attacked services...

Critical Browser Wallet Vulnerabilities Enable Unauthorized Fund Transfers

Researchers have disclosed a series of alarming vulnerabilities in popular browser-based cryptocurrency wallets that...

APT34 Hackers Use Port 8080 for Fake 404 Responses and Shared SSH Keys

Researchers have uncovered early indicators of malicious infrastructure linked to APT34, also known as...

Hackers Exploit Weaponized Word Docs to Steal Windows Login Credentials

A sophisticated phishing campaign has been uncovered by Fortinet’s FortiGuard Labs, targeting Windows users...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Crypto Platform OKX Suspends Tool Abused by North Korean Hackers

Cryptocurrency platform OKX has announced the temporary suspension of its Decentralized Exchange (DEX) aggregator...

Authorities Seize $31 Million Linked to Crypto Exchange Hack

U.S. authorities announced the seizure of $31 million tied to the 2021 Uranium Finance...

Stablecoin Bank Hit by Cyberattack, Loses $49.5M to Hackers

The cryptocurrency sector faced one of its most significant security breaches this year as...