CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CPU_HU: Fileless cryptominer targeting exposed PostgreSQL with over 1.5K victims

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 1481

As cited

Copy frozen at (site build).

threat intel

CPU_HU: Fileless cryptominer targeting exposed PostgreSQL with over 1.5K victims

Attackers are exploiting exposed PostgreSQL databases in cloud environments to deploy fileless cryptominers, affecting over 1,500 victims. The campaign, named CPU_HU, leverages weak credentials or misconfigurations to gain database access and execute malicious payloads without writing files to disk. This method allows attackers to evade traditional endpoint detection while consuming compute resources for cryptocurrency mining.

Why it matters: Database administrators and cloud security teams need to audit PostgreSQL instances for weak credentials, network exposure, and unauthorized command execution privileges, as attackers are actively targeting these weaknesses at scale.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary