A new cryptojacking campaign called JINX-0132 targets misconfigured DevOps servers including Docker, Gitea, HashiCorp Consul, and Nomad to mine cryptocurrencies. Attackers exploit known vulnerabilities and misconfigurations, downloading tools directly from GitHub to avoid attribution. The campaign notably represents the first documented exploitation of Nomad misconfigurations in the wild, with compromised instances managing hundreds of clients worth tens of thousands of dollars monthly in computing resources.
Sort: