Hackers Harnessed Ghost Servers for Mining Cryptocurrency

avatar
· Lượt xem 9,048

Popular blogging platform Ghost, and tech firms LineageOS and Digicert were the latest victims for cryptomining attacks, a kind of malware that harnessed their computing powers for mining cryptocurrencies.

Ghostb confirmed it has been hacked as attackers abused the vulnerabilities in popular infrastructure tool Salt and gained access to the Ghost (Pro) sites and Ghost.org billing services.

 

The open-source platform, which has more than 2 million installs and 750,000 registered users, said its developers quickly detected flaws in the Salt configuration management framework. The mining attempt spiked CPUs and quickly overloaded most of their systems, which alerted us to the issue immediately.

Ghost, which counts big names customers such as Mozilla, NASA, and DuckDuckGo, said customer information and user credentials weren’t infiltrated during the incident.

“All traces of the crypto-mining virus were successfully eliminated yesterday, all systems remain stable, and we have not discovered any further concerns or issues on our network. The team is now working hard on remediation to clean and rebuild our entire network,” the company said on its status page.

The developer of Salt, Saltstack, has introduced two updates to address the vulnerabilities in its tool, which is widely used by data centers and in cloud-based environments for server configuration and monitoring.

Ghost isn’t the first company’s cloud to be hacked by cryptocurrency miners. Several businesses and government agencies have fallen victim to cryptojacking attacks over the past few years.

Virginia-based bank Capital One revealed in July that more than 100 million of its customers had their personal data exposed in a hack. The hack also affected 6 million in Canada, and the leaked data was used for hijacking the resources of comprised machines to solve mathematical problems and collect cryptocurrency rewards.

Cryptojacking, which is also known as cryptomining malware or coinjacking, has been a rampant practice. As Finance Magnates previously reported, instances of such malware have shot up over the last two years, leading commentators to warn of an epidemic.

Tuyên bố miễn trừ trách nhiệm: Nội dung trên chỉ thể hiện quan điểm của tác giả hoặc khách mời. Nó không đại diện cho bất kỳ quan điểm hoặc vị trí nào của FOLLOWME và không có nghĩa là FOLLOWME đồng ý với tuyên bố hoặc mô tả của nó, cũng không cấu thành bất kỳ lời khuyên đầu tư nào. Đối với tất cả các hành động do khách truy cập thực hiện dựa trên thông tin do cộng đồng FOLLOWME cung cấp, cộng đồng không chịu bất kỳ hình thức trách nhiệm pháp lý nào trừ khi được cam kết bằng văn bản.

Trang web cộng đồng giao dịch FOLLOWME: www.followme.asia

Ủng hộ nếu bạn thích
avatar
Trả lời 0

Tải thất bại ()

  • tradingContest