Monday, November 25, 2024
HomeCryptocurrency hackHackers Abused Oracle WebLogic Server for Mining Cryptocurrencies

Hackers Abused Oracle WebLogic Server for Mining Cryptocurrencies

Published on

There is a rapid growth in cryptocurrency attacks from the mid of 2017, mining cryptocurrency requires more computing power, which requires significant amounts of energy. Attackers abuses Oracle WebLogic Server vulnerability to deliver Monero Miner Payloads.

As long as your server has RCE vulnerability attackers take an advantage of it and include malicious scripts. The cryptocurrency attacks not only compromise the system, it consumes all the system resources.

Attackers use already patched vulnerability CVE-2017-10271 that allows remote code execution to deliver cryptocurrency miners payload. Security researchers from TrendMicro spotted the abuse of vulnerability by the cybercriminal to mine Monero.

Once the Coinminer_MALXMR[.]JL-PS is executed it downloads three files, one autostart component and two autostart components one for Windows 64-bit & and another for 32-bit.Trend Micro detected it as Coinminer_TOOLXMR[.]JL-WIN64 and Coinminer_MALXMR[.]JLT-WIN32.
- Advertisement - SIEM as a Service
Oracle WebLogic Server
Payload Execution

Based on the Windows operating system architecture it decides which miner to run, either 64-bit variant or 32-bit variant of an XMRig Monero miner.

Last week attackers targetted Apache CouchDB patched vulnerabilities CVE-2017-12635 (Apache CouchDB JSON Remote Privilege Escalation Vulnerability) and CVE-2017-12636 (Apache CouchDB _config Command Execution) to mine Cryptocurrency.

It is not the first Oracle Weblogic were Exploited, last month attackers used the same vulnerability to install and run crypto miners. Following are the version affected with the vulnerability 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0.

Hackers taking each and every opportunity for mining cryptocurrencies, even they inserted Cryptocurrency Mining Script with the embedded videos in word documents.

And if the user plays the video the Embedded script will be executed and suddenly system CPU Process getting higher and can reach up to 99%.

It is recommended to update your application regularly to mitigate the threats that exploit system vulnerabilities.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Threat Actors Exploit Google Docs And Weebly Services For Malware Attacks

Phishing attackers used Google Docs to deliver malicious links, bypassing security measures and redirecting...

Python NodeStealer: Targeting Facebook Business Accounts to Harvest Login Credentials

The Python-based NodeStealer, a sophisticated info-stealer, has evolved to target new information and employ...

XSS Vulnerability in Bing.com Let Attackers Send Crafted Malicious Requests

A significant XSS vulnerability was recently uncovered in Microsoft’s Bing.com, potentially allowing attackers to...

Meta Removed 2 Million Account Linked to Malicious Activities

 Meta has announced the removal of over 2 million accounts connected to malicious activities,...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

New Android Malware SpyAgent Taking Screenshots Of User’s Devices

SpyAgent, a newly discovered Android malware, leverages OCR technology to extract cryptocurrency recovery phrases...

North Korean Hackers Employing New Tactic To Acruire Remote Jobs

North Korean threat actors behind the Contagious Interview and WageMole campaigns have refined their...

Critical Atlassian Vulnerability Exploited To Connect Servers In Mining Networks

Hackers usually shift their attention towards Atlassian due to flaws in its software, especially...