Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

3/13/2019
02:45 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
100%
0%

Enterprise Cloud Infrastructure a Big Target for Cryptomining Attacks

Despite the declining values of cryptocurrencies, criminals continue to hammer away at container management platforms, cloud APIs, and control panels.

The cloud-based infrastructures that enterprise organizations are increasingly using to run their business applications have become a major target for illicit cryptomining operations.

According to new research from AT&T Cybersecurity, cryptomining has become the primary reason for most cloud infrastructure attacks these days. There's no sign the attacks will let up soon, either, despite the drop in values of major cryptocurrencies, the vendor said in a report Wednesday.

Cryptojacking — or attacks where an organization's (or an individual's) computers are surreptitiously used to mine for Monero and other cryptocurrencies — has emerged as a major problem over the last 18 months or so.

Cybercriminals have been extensively planting mining tools such as Coinhive on hacked websites and quietly using the systems of people visiting the sites to mine for cryptocurrencies. They have also been deploying mining software on larger, more powerful enterprise servers and on cloud infrastructure for the same purpose.

"Hijacking servers to mine currency really picked up in 2017, at the height of the cryptocurrency boom when prices were at the highest and the potential rewards were very significant," says Chris Dorman, security researcher at AT&T Cybersecurity. "Even though bitcoin prices have dropped 80% since their peak, the prevalence of server cryptojacking continues."

AT&T Cybersecurity's researchers examined cryptomining attacks against a range of cloud infrastructure targets. Container management platforms are one of them. The security vendor says its researchers have observed attackers using unauthenticated management interfaces and open APIs to compromise container management platforms and use them for cryptomining.

As one example, the researchers pointed to an attack that security vendor RedLock first reported last year, where a threat actor compromised an AWS-hosted Kubernetes server belonging to electric carmaker Tesla and then used it to mine for Monero. AT&T Cybersecurity said it has investigated other similar incidents involving malware served from the same domain that was used in the Tesla attack.

Attackers have also been frequently targeting the control panels of web hosting services, as well. In April 2018, for instance, an adversary took advantage of a previously unknown vulnerability in the open source Vesta hosting control panel (VestaCP) to install a Monero miner on web hosts running the vulnerable software.

Container management systems and control panels are not the only cloud infrastructure targets. API keys are another favorite. AT&T Cybersecurity says many attackers are running automatic scans of the web and of sites such as GitHub for openly accessible API keys, which they then use to compromise the associated accounts.

The trend requires due diligence on multiple fronts. Almost all server-side exploits in the cloud, for instance, stem from exploits in software such as Apache Struts and Drupal, Dorman says. "Typically, we see the attackers start scanning the Internet for machines to compromise within two or three days of an exploit becoming available," he notes. So, keeping machines patched fairly quickly is key.

Similarly, ensuring complex password use and enforcing account lockouts is critical to preventing attackers from simply brute-forcing passwords to cloud servers, he says.

In terms of cloud accounts being compromised — when an attacker steals the root AWS key, for instance — there are free tools available to check all public source code and to verify if any credentials have been accidentally published, Dorman notes.

Malicious Docker images are yet another avenue of attack. Cybercriminals are hiding cryptominers in prebuilt Docker images and uploading them to Docker Hub, AT&T Cybersecurity said. Prebuilt images are popular among administrators because they can help reduce the time required to set up and configure a container app. However, if the image is malicious, organizations can end up running a cryptominer as well. So far, though, only a relatively small number of organizations have reported downloading and running malicious containers, AT&T Cybersecurity said.

For enterprises, cryptomining attacks in the cloud are a little trickier to address than attacks on on-premises systems. Deploying network detection tools, for instance, typically tends to be more difficult in the cloud. "You may have to rely upon your cloud provider letting you know if they see malicious traffic," Dorman says.

It's also important to centralize all logs provided by your cloud provider and to ensure that alerts are generated off of suspicious events. "For example, if you see someone log in to your root AWS account, and that isn't normal for your environment, you should investigate immediately."

Related Content:

 

 

 

Join Dark Reading LIVE for two cybersecurity summits at Interop 2019. Learn from the industry's most knowledgeable IT security experts. Check out the Interop agenda here.

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 6/1/2020
Stay-at-Home Orders Coincide With Massive DNS Surge
Robert Lemos, Contributing Writer,  5/27/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: It's the latest version of antivirus.
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-13759
PUBLISHED: 2020-06-02
rust-vmm vm-memory before 0.1.1 and 0.2.x before 0.2.1 allows attackers to cause a denial of service (loss of IP networking) because read_obj and write_obj do not properly access memory. This affects aarch64 (with musl or glibc) and x86_64 (with musl).
CVE-2020-7662
PUBLISHED: 2020-06-02
websocket-extensions npm module prior to 1.0.4 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other characte...
CVE-2020-7663
PUBLISHED: 2020-06-02
websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other charact...
CVE-2020-12017
PUBLISHED: 2020-06-02
GE Grid Solutions Reason RT Clocks, RT430, RT431, and RT434, all firmware versions prior to 08A05. The device’s vulnerability in the web application could allow multiple unauthenticated attacks that could cause serious impact. The vulnerability may allow an unauthenticated attacke...
CVE-2018-18623
PUBLISHED: 2020-06-02
Grafana 5.3.1 has XSS via the "Dashboard > Text Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.