BTC $62,994.20 +0.00%
ETH $1,878.83 -0.02%
BNB $604.50 -0.99%
XRP $1.00 -0.05%
SOL $75.34 +0.24%
TRX $0.3308 -0.40%
DOGE $0.0698 -0.24%
ADA $0.1777 -0.68%
BCH $203.52 -1.12%
LINK $9.38 +0.68%
HYPE $57.34 +1.88%
AAVE $85.95 -0.68%
SUI $0.6767 -0.74%
XLM $0.1567 -0.85%
ZEC $487.51 -0.37%
BTC $62,994.20 +0.00%
ETH $1,878.83 -0.02%
BNB $604.50 -0.99%
XRP $1.00 -0.05%
SOL $75.34 +0.24%
TRX $0.3308 -0.40%
DOGE $0.0698 -0.24%
ADA $0.1777 -0.68%
BCH $203.52 -1.12%
LINK $9.38 +0.68%
HYPE $57.34 +1.88%
AAVE $85.95 -0.68%
SUI $0.6767 -0.74%
XLM $0.1567 -0.85%
ZEC $487.51 -0.37%

Hackers exploit public DevOps tools for cryptocurrency mining attacks

2025-06-04 23:57:46

ChainCatcher message, security company Wiz has discovered that a hacker organization codenamed JINX-0132 is massively exploiting configuration vulnerabilities in DevOps tools for cryptocurrency mining attacks. The attack primarily targets tools such as HashiCorp Nomad/Consul, Docker API, and Gitea, with approximately 25% of cloud environments at risk. The attack methods include: deploying XMRig mining software using Nomad's default configuration, executing malicious scripts through Consul's unauthorized API, and controlling exposed Docker API to create mining containers.

app_icon
ChainCatcher Building the Web3 world with innovations.