DIRECTORY

  • Alerts
  • APTs
  • Blog
  • Books
  • Certifications
  • Cheat Sheets
  • Courses
  • Cyber Briefing
  • CyberDecoded
  • CyberReview
  • CyberStory
  • CyberTips
  • Definitions
  • Domains
  • Entertainment
  • FAQ
  • Frameworks
  • Hardware Tools
  • Incidents
  • Malware
  • News
  • Papers
  • Podcasts
  • Quotes
  • Reports
  • Tools
  • Threats
  • Tutorials
No Result
View All Result
  • Login
  • Register
  • Cyber Citizens
  • Cyber Professionals
  • Institutions
CyberMaterial
Get Help
  • Cyber Citizens
  • Cyber Professionals
  • Institutions
CyberMaterial
No Result
View All Result
Get Help
CyberMaterial
Home Alerts

Dero cryptocurrency targeted by hackers

March 16, 2023
Reading Time: 2 mins read
in Alerts

 

Cybersecurity firm CrowdStrike has identified the first ever cryptocurrency-jacking campaign targeting the privacy-focused cryptocurrency Dero. The operation has targeted US-based servers using Kubernetes infrastructure since February 2023.

While rewards for cryptojacking fell by between 50% and 90% in the 2022 crypto crash, Dero has continued to offer larger rewards to miners, making it a lucrative target for hackers.

The cryptocurrency’s privacy and anonymity features make it difficult to track funds in Dero wallets, and transactions cannot be followed in a way that reveals who sent or received coins.

The campaign operators find and target exposed Kubernetes clusters that can be accessed anonymously, along with non-standard ports that can be accessed from the internet.

Attackers can bypass authentication to deploy a Kubernetes DaemonSet, which in turn deploys a malicious pod on each node of the Kubernetes cluster. The mining efforts by the pods are contributed back to a community pool, which distributes the reward equally among its contributors through their digital wallet.

These attackers are only attempting to mine for Dero and are not trying to move laterally to attack other resources or scan the internet for discovery.

The attack flow of the Dero campaign is nearly identical to that of a Monero-focused campaign. Both campaigns are trying to find undiscovered Kubernetes attack surfaces, and are battling it out. The Monero campaign kicks out the DaemonSets used for Dero cryptojacking in the Kubernetes cluster before taking it over.

The Monero campaign deliberately deletes existing DaemonSets to disrupt the Dero campaign before taking over the cluster and using the deployed resources for its own purposes. The fact that these campaigns are battling each other for control of vulnerable servers highlights the ongoing evolution of cryptojacking tactics.

Read More

Tags: AlertsAlerts 2023CISACISA InsightsCISA ReportCryptocurrenciesDeroMarch 2023Vulnerabilities
0
VIEWS
ADVERTISEMENT

Related Posts

Unpatched IBM file transfer software at Risk

Unpatched IBM file transfer software at Risk

March 31, 2023
Osprey Pump Controller Vulnerabilities

Osprey Pump Controller Vulnerabilities

March 31, 2023
Super FabriXss vulnerability in Azure

Super FabriXss vulnerability in Azure

March 31, 2023
Tool for Cloud Credential Harvesting

Tool for Cloud Credential Harvesting

March 31, 2023

More Articles

Tool

CASRA Incident Response

June 16, 2022
Cyber101

Zero Trust (ZT) – Definitions

March 27, 2023
Alerts

ICONICS and Mitsubishi Electric security advisory

July 26, 2022
Tool

Security Ratings

June 15, 2022

Security through data

Cybersecurity Domains

  • API Security
  • Business Continuity
  • Career Development
  • Compliance
  • Cryptography
  • HSM
  • KPIs / KRIs
  • Penetration Testing
  • Shift Left
  • Vulnerability Scan

Emerging Technologies

  • 5G
  • Artificial Intelligence
  • Blockchain
  • Cryptocurrency
  • Deepfake
  • E-Commerce
  • Healthcare
  • IoT
  • Quantum Computing

Frameworks

  • CIS Controls
  • CCPA
  • GDPR
  • NIST
  • 23 NYCRR 500
  • HIPAA

Repository

  • Books
  • Certifications
  • Definitions
  • Documents
  • Entertainment
  • Quotes
  • Reports

Threats

  • APTs
  • DDoS
  • Insider Threat
  • Malware
  • Phishing
  • Ransomware
  • Social Engineering

© 2023 | CyberMaterial | All rights reserved.

World’s #1 Cybersecurity Repository

  • About
  • Legal and Privacy Policy
  • Site Map
No Result
View All Result
  • Audience
    • Cyber Citizens
    • Cyber Professionals
    • Institutions
  • Highlights
    • Blog
    • CyberDecoded
    • Cyber Review
    • CyberStory
    • CyberTips
  • Cyber Risks
    • Alerts
    • Attackers
    • Domains
    • Incidents
    • Threats
  • Opportunities
    • Events
    • Jobs
  • Repository
    • Books
    • Certifications
    • Cheat Sheets
    • Courses
    • Definitions
    • Frameworks
    • Games
    • Hardware Tools
    • Memes
    • Movies
    • Papers
    • Podcasts
    • Quotes
    • Reports
  • Report Cyber Incident
  • GET HELP

Subscribe to our newsletter

© 2022 Cybermaterial - Security Through Data .

Welcome Back!

Sign In with Google
Sign In with Linked In
OR

Forgotten Password? Sign Up

Create New Account!

Sign Up with Google
Sign Up with Linked In
OR

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.