Cloud infrastructure attacks are becoming more sophisticated all the time, and according to a new security report, the majority of them have one major goal: mining cryptocurrencycryptocurrency.
A new report issued today by Aqua Security’s cybersecurity-centric Team Nautilus, entitled “Evolution of Attacks in the Wild on Container Infrastructure,” relayed the results of extensive research and testing into the growing trend of attacks on cloud servers.
According to a release, there is a “growing, organized and increasingly sophisticated pattern of attacks on cloud native infrastructure.” And while the majority of the tracked attackers sought to use cloud computing resources to minemine crypto, the release adds that the “methods used open the door for higher-value targets that leverage security gaps in container software supply chains and runtime environments.”
Aqua Security traced cloud infrastructure attacks for a full year, tracking more than 16,000 individual attacks back to various international locations. The report adds that there has been a dramatic uptick in such attacks since the start of 2020, suggesting an organized and systematic approach.
Aqua released a new 70-page #threat report by Team Nautilus, Aqua’s #cybersecurity research team, that reveals a growing, organized and increasingly sophisticated pattern of attacks on #cloudnative infrastructure.
“The attacks we observed are a significant step up in attacks targeting cloud native infrastructure,” said Team Nautilus head Idan Revivo, in a release. “We expect a further increase in sophistication, the use of evasion techniques and diversity of the attack vectors and objectives, since the widespread use of cloud native technologies makes them a more lucrative target for bad actors.”
The report suggests that “sophisticated evasion techniques” are being deployed, including using “vanilla” images that seem to be uncompromised, disabling other resource-draining malware, having time-delayed downloads for payloads, and using 64-bit encryption.
According to the report, about 95% of the attacks were aimed at mining cryptocurrency, and the total number of attacks jumped up 250% year-over-year.
Guardicore, a data center and cloud security company, issued a report today detailing an extensive campaign by a botnet to hijack Microsoft SQL Server (MS-SQL) machines around the globe and force them to mine the cryptocurrencies Monero and Vollar.
Dubbed “Vollgar” by the company—a portmanteau of Vollar and vulgar—the campaign has continued on since it was first detected in May 2018, steadily infecting about 3,000 new machines daily across all sorts of industries, including healthcare and teleco...
This isn’t the first time we’ve heard about malicious attacks on servers with the aim of mining cryptocrypto. Earlier this year, security firm Guardicore issued a report about an active malware campaign that was hijacking Microsoft SQL Server (MS-SQL) machines globally to mine Monero and Vollar. It also noted that some attacks sought to disrupt other malware on hijacked systems, in order to fully command system resources.
North Korean hackers are luring crypto professionals into elaborate fake job interviews designed to steal their data and deploy sophisticated malware on their devices.
A new Python-based remote access trojan called "PylangGhost," links malware to a North Korean-affiliated hacking collective called "Famous Chollima," also known as "Wagemole,” threat intelligence research firm Cisco Talos reported on Wednesday.
"Based on the advertised positions, it is clear that the Famous Chollima is broadly tar...
A previously unreported data breach has exposed more than 16 billion login credentials, making it one of the largest compilations of stolen personal data ever discovered.
First reported by Cybernews, the trove of data includes credentials for widely used services, including Facebook, Google, Telegram, and GitHub, as well as access to corporate, developer, and government websites.
Researchers from Cybernews said the information likely comes from a mix of infostealer malware logs, credential stuff...
Quantum computers weren’t expected to pose a threat to Bitcoin’s security anytime soon. But IBM has launched a project that could expedite the timeline: the world’s first fault-tolerant quantum computer, set to debut by 2029.
Despite their ability to calculate in multiple directions simultaneously, current-generation quantum computers have high error rates. Without fault tolerance, and the ability to detect and correct errors as they happen, quantum computers can’t run complex algorithms that wo...