BTC PULSE
  • News
    • Altcoins
    • Blockchain
    • Bitcoin
    • Ethereum
    • NFT
    • Regulation
    • WEB 3.0
  • Price Prediction
  • Learn
  • Events
  • Advertise
No Result
View All Result
Play Now
  • News
    • Altcoins
    • Blockchain
    • Bitcoin
    • Ethereum
    • NFT
    • Regulation
    • WEB 3.0
  • Price Prediction
  • Learn
  • Events
  • Advertise
No Result
View All Result
BTC PULSE
No Result
View All Result
Play Now
Home Blockchain

Hackers Exploit Old HTTP File Server to Install Monero Miners

by Dan K
Jul 5, 2024 - 4:17 pm
in Blockchain
Cybercriminals exploiting HTTP File Server vulnerability to install Monero miners

Cybercriminals exploiting HTTP File Server vulnerability to install Monero miners

Hackers Exploit Old HTTP File Server to Install Monero Miners

Threat actors actively exploit critical vulnerabilities in older versions of Rejetto’s HTTP File Server to install Monero mining malware and other malicious software.

Critical Vulnerabilities in HTTP File Server

Researchers from BleepingComputer, drawing information from AhnLab, have identified a new attack technique used by hackers who are targeting the so-called file-sharing software – HTTP File Server (HFS). The approach involves abusing security holes in outdated software versions to inflict the users with a virus which covertly mines Monero. Users might not even notice that their resources are being used, the report said.

Exploitation Details

Attackers have discovered a vulnerability in HFS version 2.3m, and using this hole they remotely execute commands that enable them to take control of the system without any auth. Threat actors receive unauthorized access to HTTP File Server and intentionally intercept response instructions. This vulnerability will immediately escalate privileges and give access to the local as well as the whole network, simply letting bad actors through the front door, which means no security is assured at all.

Variety of Malicious Payloads

According to the alerted report issued by AhnLab, a security firm, the cases of the use of malwares in other forms rather than the simple system compromise are frequently recorded. The number of such cases is so big that to name a few examples will be to mention the tools like the XMRig, the remote access trojans (RATs) and the XenoRAT and Gh0stRAT. It is still unknown how severe these attacks on the target computers are or how much Monero has already been mined by the hidden mining activity on the affected devices, but the possible damage remains high.

Response from Rejetto

The software company, Rejetto confirmed the bug and issued a warning of the malfunction, in response to which Rejetto issued an alert and recommended all users to drop versions 2.3m through 2.4 and instead go for the more secure ones. The company has reported that the versions 2.3m – 2.4 contain discovered security vulnerabilities and therefore, they are not safe to be used,” Rejetto stated in their advisory. The developers called on the users to upgrade their systems to the secure software versions.

Why Monero?

Cybercriminals usually have a strong preference for installing XMRig on infected devices and this is because the privacy features of Monero are incredibly high, which subsequently make the transactions really hard to trace. XMRig can easily run on various hardware and it being open-source makes it very easy to modify. Moreover, it can be secretly launched in the background of the device’s processes and conceals the network traffic which makes it very difficult to detect.

Conclusion

This exploitation of older HFS versions highlights the critical need for regular software updates, and vigilance in cybersecurity practices. Users are instructed to upgrade to newer releases to block these types of attacks.

Tags: BlockchainHackMining
Dan K

Dan K

Dan K, the chief editor, is a visionary wordsmith, shaping narratives with finesse. His discerning eye for detail creates literary masterpieces.

Related Posts

Malta Financial Services Authority building representing crypto regulation leadership

Malta Regulator Assures MiCA Licenses Safe After EU Peer Review

July 11, 2025

Malta’s MFSA says no MiCA licenses are at risk after an EU review, reinforcing the country’s strong stance...

Malta’s MFSA headquarters under scrutiny from ESMA for MiCA licensing issues

EU Regulator Flags Deficiencies in Malta’s RegulatorLicensing Process

July 10, 2025

Malta’s MFSA “partially met expectations” in its MiCA license process, according to an ESMA report urging tighter crypto...

Venn Network researchers work together to neutralize a $10M backdoor exploit in smart contracts linked to DeFi protocols.

Researchers Foil $10M DeFi Backdoor Attack, Suspected Link to Lazarus Group

July 10, 2025

Researchers foiled a $10M DeFi attack by neutralizing a backdoor exploit in smart contracts, potentially linked to the...

OKX and Circle announce zero-fee USDC to USD conversions, offering smoother crypto trading experiences for users globally.

Circle and OKX Launch Zero-Fee USDC Conversions to US Dolla

July 9, 2025

OKX and Circle partner to offer zero-fee USDC to USD conversions, enhancing liquidity and simplifying the process for...

Press Releases

png 115

BTC Miner: Earn $100-$100,000 Daily – The Fastest Growing Crypto Mining Platform of 2025!

June 25, 2025

BTC Miner, the fastest growing platform in 2025, opens a new era of inclusive cryptocurrency mining, allowing everyone to participate...

image2

Could XYZVerse Overtake DOGE and SHIB? Analysts Say $0.003333 Could Explode to $10!

March 30, 2025

XYZVerse aims to outpace DOGE and SHIB, with bold $10 price goals, strong community rewards, and rising demand as it...

image1 1

Massive Institutional BTC Buys Could Launch the Next Bull Market: 5 Altcoins to Watch

March 29, 2025

Institutional Bitcoin buys may trigger a market surge. Five altcoins, including $XYZ, stand to gain—early investors could see major ROI...

image1

XRP Faces Strong Resistance While XYZVerse Gains Early Investor Attention With 10 Billion $XYZ Airdrop

March 28, 2025

XRP struggles at resistance, while XYZVerse grabs early investor attention with a 10B token airdrop and rapid growth toward a...

View All
BTC-Pulse LogoTransparent

© 2024 BTC-PULSE. Disclaimer: The content is for informational purposes only, you should not construe any such information or other material as legal, tax, investment, financial, or other advice.

News

  • Altcoins
  • Bitcoin
  • Ethereum
  • NFT
  • Regulation
  • WEB 3.0

Info

  • Learn
  • Price Prediction
  • Events
  • Press Releases
  • Sitemap

Company

  • About Us
  • Terms of Service
  • Privacy Policy
  • Contact Us
  • Advertise

©2024 BTC-PULSE – All right Reserved.

No Result
View All Result
  • News
    • Altcoins
    • Blockchain
    • Bitcoin
    • Ethereum
    • NFT
    • Regulation
    • WEB 3.0
  • Price Prediction
  • Learn
  • Events
  • Advertise