As cited
Copy frozen at (site build).
threat intel
CPU_HU: Fileless cryptominer targeting exposed PostgreSQL with over 1.5K victims
Attackers are exploiting exposed PostgreSQL databases in cloud environments to deploy fileless cryptominers, affecting over 1,500 victims. The campaign, named CPU_HU, leverages weak credentials or misconfigurations to gain database access and execute malicious payloads without writing files to disk. This method allows attackers to evade traditional endpoint detection while consuming compute resources for cryptocurrency mining.
Why it matters: Database administrators and cloud security teams need to audit PostgreSQL instances for weak credentials, network exposure, and unauthorized command execution privileges, as attackers are actively targeting these weaknesses at scale.
- Source published
- First seen by Cybersecurity Tracker