BTC PULSE
  • News
    • Altcoins
    • Blockchain
    • Bitcoin
    • Ethereum
    • NFT
    • Regulation
    • WEB 3.0
  • Price Prediction
  • Learn
  • Events
  • Advertise
No Result
View All Result
Play Now
  • News
    • Altcoins
    • Blockchain
    • Bitcoin
    • Ethereum
    • NFT
    • Regulation
    • WEB 3.0
  • Price Prediction
  • Learn
  • Events
  • Advertise
No Result
View All Result
BTC PULSE
No Result
View All Result
Play Now
Home Blockchain

Hackers Exploit Old HTTP File Server to Install Monero Miners

by Dan K
Jul 5, 2024 - 4:17 pm
in Blockchain
Cybercriminals exploiting HTTP File Server vulnerability to install Monero miners

Cybercriminals exploiting HTTP File Server vulnerability to install Monero miners

Hackers Exploit Old HTTP File Server to Install Monero Miners

Threat actors actively exploit critical vulnerabilities in older versions of Rejetto’s HTTP File Server to install Monero mining malware and other malicious software.

Critical Vulnerabilities in HTTP File Server

Researchers from BleepingComputer, drawing information from AhnLab, have identified a new attack technique used by hackers who are targeting the so-called file-sharing software – HTTP File Server (HFS). The approach involves abusing security holes in outdated software versions to inflict the users with a virus which covertly mines Monero. Users might not even notice that their resources are being used, the report said.

Exploitation Details

Attackers have discovered a vulnerability in HFS version 2.3m, and using this hole they remotely execute commands that enable them to take control of the system without any auth. Threat actors receive unauthorized access to HTTP File Server and intentionally intercept response instructions. This vulnerability will immediately escalate privileges and give access to the local as well as the whole network, simply letting bad actors through the front door, which means no security is assured at all.

Variety of Malicious Payloads

According to the alerted report issued by AhnLab, a security firm, the cases of the use of malwares in other forms rather than the simple system compromise are frequently recorded. The number of such cases is so big that to name a few examples will be to mention the tools like the XMRig, the remote access trojans (RATs) and the XenoRAT and Gh0stRAT. It is still unknown how severe these attacks on the target computers are or how much Monero has already been mined by the hidden mining activity on the affected devices, but the possible damage remains high.

Response from Rejetto

The software company, Rejetto confirmed the bug and issued a warning of the malfunction, in response to which Rejetto issued an alert and recommended all users to drop versions 2.3m through 2.4 and instead go for the more secure ones. The company has reported that the versions 2.3m – 2.4 contain discovered security vulnerabilities and therefore, they are not safe to be used,” Rejetto stated in their advisory. The developers called on the users to upgrade their systems to the secure software versions.

Why Monero?

Cybercriminals usually have a strong preference for installing XMRig on infected devices and this is because the privacy features of Monero are incredibly high, which subsequently make the transactions really hard to trace. XMRig can easily run on various hardware and it being open-source makes it very easy to modify. Moreover, it can be secretly launched in the background of the device’s processes and conceals the network traffic which makes it very difficult to detect.

Conclusion

This exploitation of older HFS versions highlights the critical need for regular software updates, and vigilance in cybersecurity practices. Users are instructed to upgrade to newer releases to block these types of attacks.

Tags: BlockchainHackMining
Dan K

Dan K

Dan K, the chief editor, is a visionary wordsmith, shaping narratives with finesse. His discerning eye for detail creates literary masterpieces.

Related Posts

Tether Gold XAUt token listed on Thai crypto exchange Maxbit backed by PTG Energy

Tether Gold Debuts in Thailand with Maxbit Exchange Listing

May 13, 2025

Tether Gold debuts in Thailand on Maxbit, enabling trading of tokenized gold backed by physical reserves under SEC-regulated...

Courtroom exterior symbolizing federal legal proceedings in the Samourai Wallet case

Feds Reject Claims of Withholding Key Evidence in Samourai Wallet Case

May 12, 2025

Prosecutors deny delaying disclosure in the Samourai Wallet case, saying FinCEN’s informal view on licensing was shared months...

Coinbase introduces nonstop regulated BTC and ETH futures trading after $2.9B Deribit acquisition

Coinbase’s $2.9B Deribit Deal Ignites 24/7 U.S.-Regulated BTC & ETH Futures

May 11, 2025

Coinbase debuts 24/7 U.S.-regulated BTC & ETH futures and acquires Deribit for $2.9B, signaling a major leap in...

SEC Commissioner Hester Peirce and Wormhole’s Cathy Yoon discussing crypto regulation and the sandbox concept

SEC’s Hester Peirce Calls for Crypto Sandbox, But Wormhole’s Legal Chief Pushes Back

May 10, 2025

Hester Peirce backs a crypto sandbox at the SEC, but Wormhole’s Cathy Yoon warns it could lead to...

Press Releases

image2

Could XYZVerse Overtake DOGE and SHIB? Analysts Say $0.003333 Could Explode to $10!

March 30, 2025

XYZVerse aims to outpace DOGE and SHIB, with bold $10 price goals, strong community rewards, and rising demand as it...

image1 1

Massive Institutional BTC Buys Could Launch the Next Bull Market: 5 Altcoins to Watch

March 29, 2025

Institutional Bitcoin buys may trigger a market surge. Five altcoins, including $XYZ, stand to gain—early investors could see major ROI...

image1

XRP Faces Strong Resistance While XYZVerse Gains Early Investor Attention With 10 Billion $XYZ Airdrop

March 28, 2025

XRP struggles at resistance, while XYZVerse grabs early investor attention with a 10B token airdrop and rapid growth toward a...

BTC

Popular Memecoin MEW Pledges $10,000 to Pasadena Humane Organization to Aid Animals Affected by California Wildfires

January 20, 2025

MEW memecoin donates $10K to Pasadena Humane for wildfire-affected animals. Join the mission to aid pets and wildlife in crisis...

View All
BTC-Pulse LogoTransparent

© 2024 BTC-PULSE. Disclaimer: The content is for informational purposes only, you should not construe any such information or other material as legal, tax, investment, financial, or other advice.

News

  • Altcoins
  • Bitcoin
  • Ethereum
  • NFT
  • Regulation
  • WEB 3.0

Info

  • Learn
  • Price Prediction
  • Events
  • Press Releases
  • Sitemap

Company

  • About Us
  • Terms of Service
  • Privacy Policy
  • Contact Us
  • Advertise

©2024 BTC-PULSE – All right Reserved.

No Result
View All Result
  • News
    • Altcoins
    • Blockchain
    • Bitcoin
    • Ethereum
    • NFT
    • Regulation
    • WEB 3.0
  • Price Prediction
  • Learn
  • Events
  • Advertise