ZeroHour
The Recordpublished ()ingested

Crypto-mining botnet modifies CPU configurations to increase its mining power

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-11610
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbit

The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace lookups.

NVD description · AI analysis pending
8.887% PoC
  • supervisord supervisor
  • supervisord fedora
  • supervisord debian linux
  • +1 more
CVE-2020-14882
Remote Code Execution in Oracle WebLogic Server

CVE-2020-14882 is a remote code execution vulnerability in Oracle WebLogic Server; its relationship to CVE-2020-14750 (a WebLogic administration console flaw) indicates it is reachable over the network, likely without authentication. An attacker who can reach a vulnerable WebLogic instance can trigger the flaw and execute arbitrary code in the context of the server. Successful exploitation can yield full control of the affected host, enabling data theft, lateral movement, and potentially ransomware deployment (ransomware use is currently unknown). Any organization running Oracle WebLogic Server is affected; WebLogic is widely deployed as a Java application server in large enterprises and government networks, and instances are frequently exposed to the internet. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) and carries a maximum EPSS score of 100%, indicating confirmed in-the-wild exploitation.

Do: Apply Oracle's WebLogic Server updates per vendor instructions immediately, as this is a required action under the CISA KEV listing. Inventory environments for WebLogic deployments (commonly listening on ports 7001/7002), prioritize patching internet-facing instances, and restrict or firewall access to the WebLogic administration console until patched. Review access logs for signs of exploitation, and treat unpatched, externally reachable WebLogic servers as high risk given the 100% EPSS score and confirmed in-the-wild exploitation.

9.8100% KEV PoC ×3
  • Oracle WebLogic Server
large≈50,000–100,000 internet-exposed WebLogic systems (public internet-wide scan counts around 2020); many more deployed internally in enterprise networks
Full article351 words · extracted from therecord.media · click to collapse

A crypto-mining botnet is modifying CPU configurations on hacked Linux servers in order to increase the performance and output of its cryptocurrency mining code.

The attacks, detected by cloud security firm Uptycs, represent the first instances where a threat actor modifies a processor's MSR to disable a CPU feature called hardware prefetcher.

Enabled by default on most CPUs, hardware prefetching allows a processor to load data in its cache memory based on the operations that are likely to be required in the near future.

When the CPU deals with repetitive computations, hardware prefetching can help improve performance.

Model-specific registers (MSR) are a set of control registers available on x86 CPUs that can be used to manage various features, including enabling and disabling hardware prefetching.

Someone read the documentation

In a report published last week, Uptycs researchers said they spotted a crypto-mining botnet in June 2021 that was breaching Linux servers, downloading the Linux MSR driver, and then disabling hardware prefetching before installing a version of XMRig, a common app used for cryptocurrency mining by both legitimate users and malware gangs.

Uptycs believes the attacker got the idea to disable hardware prefetching after reading the XMRig documentation, where it is claimed that XMRig can gain a 15% speed boost if the feature is disabled.

Right now, the attacks are limited to Linux servers, Uptycs said.

Per the company's report, the botnet has been seen using exploits for CVE-2020-14882 and CVE-2017-11610 to gain access to Linux systems running Oracle WebLogic or Supervisord before disabling hardware prefetching and installing XMRig.

Prior to the attacks spotted this summer, Uptycs said the same botnet had been active since at least December 2020 and had previously targeted servers running MySQL, Tomcat, Oracle WebLogic, and Jenkins, suggesting that the botnet could easily switch targets and target other web-based technologies if it needed to.

No previous article

No new articles

Catalin Cimpanu

is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/crypto-mining-botnet-modifies-cpu-configurations-to-increase-its-mining-power