Monday, January 20, 2025
HomeCyber AttackHackers Hijacked Misconfigured Servers For Live Streaming Sports

Hackers Hijacked Misconfigured Servers For Live Streaming Sports

Published on

SIEM as a Service

Follow Us on Google News

Recent threat hunting activities focused on analyzing outbound network traffic and binaries within containerized environments.

By cross-referencing honeypot data with threat intelligence platforms, researchers identified suspicious network events linked to the execution of the benign tool ffmpeg.

Although this particular instance was not inherently malicious, it did raise concerns due to the unusual context in which it occurred and the possibility that it could be misused. 

Jupyter environments, while powerful, pose security risks when misconfigured, as unsecured access, token mishandling, and a lack of firewalls can expose sensitive data and code to unauthorized users. 

The threat to revenue streams is posed by the illegal streaming of sports, which is made possible by easily accessible tools and high-speed internet.

Maximizing Cybersecurity ROI: Expert Tips for SME & MSP Leaders – Attend Free Webinar

Hackers Hijacked Misconfigured Servers

To mitigate these threats, robust security measures like IP restrictions, strong authentication, and encryption are crucial for Jupyter environments, while sports organizations employ AI-based detection, watermarking, and legal actions to combat piracy.

The entire attack flow

Threat actors exploited unauthenticated access to Jupyter Lab and Notebook servers, initially gaining unauthorized access and then escalated privileges to execute remote code, specifically downloading and running ffmpeg to stream sports events. 

While this initial attack might seem benign, it underscores the potential for severe consequences, including data theft, manipulation, or corruption of AI/ML processes, leading to significant financial and reputational damage. 

Traceeshark main view

Aqua Tracee captured Linux system events, including network activity, file operations, and memory dumps, and consolidated them into a Wireshark-compatible .pcapng file, which was then analyzed using Traceeshark, a modified version of Wireshark, to identify suspicious activity. 

The analysis focused on the process tree, which revealed numerous unusual ffmpeg executions with a pattern of IP addresses, indicating potential malicious activity.

While the overall volume of events was relatively small, the specific nature of these events raised significant security concerns. 

Traceeshark’s process tree

Aqua investigated a misconfigured JupyterLab server attack using Traceeshark’s container and important filters.

The attacker discovered the server, downloaded ffmpeg from an untrusted source (MediaFire), and executed the tool to stream content from x9pro.xyz to ustream.tv. 

Analyzing the command revealed the attacker’s intent to discreetly capture and stream content, possibly for ad revenue or subscriptions; it identified the targeted source as Qatari beIN Sports broadcasts, and the attacker’s IP address suggested an Algerian origin.  

Unprotected Jupytar Notebook

Behavioral analysis, when coupled with proactive threat hunting, is essential for identifying hidden attacks, especially in complex environments like JupyterLab and Jupyter Notebook. 

Security teams are able to uncover sophisticated threats that may be missed by traditional security tools if they conduct an analysis of patterns and behavioral indicators. 

On the other hand, the utilization of ffmpeg for live-stream capture, despite appearing to be lawful, has the potential to be utilized for unlawful activities such as sports piracy.

Are you from SOC/DFIR Teams? – Analyse Malware Files & Links with ANY.RUN -> Try for Free

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies.

Latest articles

Multiple Azure DevOps Vulnerabilities Let Inject CRLF Queries & Rebind DNS

Researchers uncovered several significant vulnerabilities within Azure DevOps, specifically focusing on potential Server-Side Request...

Hackers Weaponize npm Packages To Steal Solana Private Keys Via Gmail

Socket’s threat research team has identified a series of malicious npm packages specifically designed...

Hackers Weaponize MSI Packages & PNG Files to Deliver Multi-stage Malware

Researchers have reported a series of sophisticated cyber attacks aimed at organizations in Chinese-speaking...

New IoT Botnet Launching Large-Scale DDoS attacks Hijacking IoT Devices

Large-scale DDoS attack commands sent from an IoT botnet's C&C server targeting Japan and...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

Multiple Azure DevOps Vulnerabilities Let Inject CRLF Queries & Rebind DNS

Researchers uncovered several significant vulnerabilities within Azure DevOps, specifically focusing on potential Server-Side Request...

Hackers Weaponize npm Packages To Steal Solana Private Keys Via Gmail

Socket’s threat research team has identified a series of malicious npm packages specifically designed...

Hackers Weaponize MSI Packages & PNG Files to Deliver Multi-stage Malware

Researchers have reported a series of sophisticated cyber attacks aimed at organizations in Chinese-speaking...