5 ms·
I agree. I would like to seem more details of how they determined it was only crypto mining. Finding only mining scripts in your logs doesn't mean they were not
by lasdfas 6y ago
I agree. I would like to seem more details of how they determined it was only crypto mining. Finding only mining scripts in your logs doesn't mean they were not running other code once they had root.
- sterlind 6y agoIt seems bizarre to me that a crypto miner got in. It wouldn't make much money on regular CPUs, and the high processor usage would immediately draw attention. So it looks like a low-effort botnet, which is embarrassing to get pwned by. (The coin mining could be a cover like you mention, but it seems unlikely since it naturally draws attention.)
- optimiz3 6y ago> It wouldn't make much money on regular CPUs Not true; some PoWs such as Random-X are designed to be most efficient CPUs.
- itsajoke 6y agoI once worked at a place where a minor piece of cloud infra got exploited. All the attacker did was run a monero miner on it.
- sterlind 6y agoHeh, in a way it makes a good bug bounty. Like if popping calc got you a trickle of income.
- vertex-four 6y agoIt’s easier to sell Monero for cash than... some random data from some random company.
- nemo136 6y agorunning the virus code in a container / vm and checking what gets modified