Business Daily Media

The Times Real Estate

.

Cloud Systems Are the New Battleground for Crypto Mining Threat Actors

Trend Micro report warns of growing attack surface for CPU-mining

HONG KONG SAR - Media OutReach - 30 March 2022 - Trend Micro Incorporated (TYO: 4704; TSE: 4704), a global cybersecurity leader, today announced a new report revealing a fierce, hour-by-hour battle for resources among malicious cryptocurrency mining groups.

To read the "A Floating Battleground Navigating the Landscape of Cloud-Based Cryptocurrency Mining" report: https://www.trendmicro.com/vinfo/hk/security/news/cybercrime-and-digital-threats/probing-the-activities-of-cloud-based-cryptocurrency-mining-groups

"Just a few hours of compromise could result in profits for the perpetrators. That's why we're seeing a continuous fight for cloud CPU resources. It's akin to a real-life capture-the-flag, with the victim's cloud infrastructure the battleground," said Stephen Hilt, Senior Threat Researcher at Trend Micro. "Threats like this need joined-up, platform-based security to ensure the bad guys have nowhere to hide. The right platform will help teams map their attack surface, assess risk, and apply for the right protection without adding excessive overheads."

Threat actors are increasingly scanning for and exploiting these exposed instances, as well as brute-forcing SecureShell (SSH) credentials, in order to compromise cloud assets for cryptocurrency mining, the report reveals. Targets are often characterized by having outdated cloud software in the cloud environment, poor cloud security hygiene, or inadequate knowledge on how to secure cloud services and thus easily exploited by threat actors to gain access to the systems.

Cloud computing investments have surged during the pandemic. But the ease with which new assets can be deployed has also left many cloud instances online for longer than needed—unpatched and misconfigured.

On one hand, this extra computing workload threatens to slow key user-facing services for victim organizations, as well as increasing operating costs by up to 600% for every infected system.

Crypto mining can also be a precursor to more serious compromise. Many mature threat actors deploy mining software to generate additional revenue before online buyers purchase access for ransomware, data theft, and more.

The Trend Micro report details the activity of multiple threat actor groups in this space, including:

Outlaw, which compromises IoT devices and Linux cloud servers by exploiting known vulnerabilities or performing brute-force SSH attacks.

TeamTNT, which exploits vulnerable software to compromise hosts before stealing credentials for other services to help it move around to new hosts and abuse any misconfigured services.

Kinsing, which sets up an XMRig kit for mining Monero and kicks any other miners off a victim system.

8220, which has been observed fighting Kinsing over the same resources. They frequently eject each other from a host and then install their own cryptocurrency miners.

Kek Security, which has been associated with IoT malware and running botnet services.

To mitigate the threat from cryptocurrency mining attacks in the cloud, Trend Micro recommends organizations to:

  • Ensure systems are up-to-date and running only the required services
  • Deploy firewall, IDS/IPS, and cloud endpoint security to limit and filter network traffic to and from known bad hosts
  • Eliminate configuration errors via Cloud Security Posture Management tools
  • Monitor traffic to and from cloud instances and filter out domains associated with known mining pools
  • Deploy rules that monitor open ports, changes to DNS routing, and utilization of CPU resources from a cost perspective

About Trend Micro

Trend Micro, a global cybersecurity leader, helps make the world safe for exchanging digital information. Fueled by decades of security expertise, global threat research, and continuous innovation, Trend Micro's cybersecurity platform protects hundreds of thousands of organizations and millions of individuals across clouds, networks, devices, and endpoints. As a leader in cloud and enterprise cybersecurity, the platform delivers a powerful range of advanced threat defense techniques optimized for environments like AWS, Microsoft, and Google, and central visibility for better, faster detection and response. With 7,000 employees across 65 countries, Trend Micro enables organizations to simplify and secure their connected world.

#TrendMicro

News from Asia

"Relaxing Jiaxing" Creative Naming Journey Launches, A Hong Kong Influencer Lead the Way in Cultural Tourism

HONG KONG SAR - Media OutReach Newswire - 7 May 2025 - Recently, a well-known travel influencer from Hong Kong was invited by Jiaxing Municipal Bureau of Culture and Tourism and Putike Internation...

Amari Bangkok: Gateway to the Vibrant Heart of the City, Creating Unforgettable Experiences at Every Moment

BANGKOK, THAILAND - Media OutReach Newswire – 7 May 2025 - Located in the dynamic heart of Thailand's capital, Amari Bangkok is an upper-upscale luxury hotel managed by ONYX Hospitality Group — a ...

INIU Expands European Footprint Through Strategic Partnership with SFR

PARIS, FRANCE - Media OutReach Newswire - 7 May 2025 - Powering ahead with innovation, INIU, a globally trusted brand in portable power solutions, is proud to bring its products to even more Fren...

Rhenus signs MoU with Inland Waterways Authority of India (IWAI)

MUMBAI, INDIA - Media OutReach Newswire - 7 May 2025 - Through the Memorandum of Understanding (MoU), leading global logistics service provider, the Rhenus Group, will operate barge services in va...

INIU Partners with Boulanger to Launch Innovative Charging Products in France

PARIS, FRANCE - Media OutReach Newswire - 7 May 2025 - INIU has expanded its partnership with France's leading electronics retailer Boulanger, making its latest innovations—MagPro Slim 5K/10K, P...

New Report Highlights Need for Ecosystem Approach to Help MSMEs in Southeast Asia Adopt More Sustainable Practices

Report by the Centre for Impact Investing and Practices (CIIP) finds growing momentum among micro, small, and medium enterprises (MSMEs) in Southeast Asia to adopt sustainability practices...

His Highness Shaikh Mohammed Bin Sultan Bin Hamdan Al Nahyan acquires Warrants of Diginex Limited to Purchase 6.75 Million Ordinary Shares of Diginex for USD$300 million via a Private Transaction

LONDON, UNITED KINGDOM - Media OutReach Newswire - 7 May 2025 - Diginex Limited ("Diginex") (NASDAQ: DGNX), a global leader in ESG sustainable RegTech, is pleased to announce that His Highness Sha...

CTF Life Title-Sponsored "Fencing Plus" Training Programme by Kai Tak Sports Initiative Officially Kicks Off

Nearly 800 Students Participate in the Selection to Become Future World Champions HONG KONG SAR - Media OutReach Newswire - 7 May 2025 - Title-sponsored by CTF Life and organised by Kai Tak Sport...

Chubb Life Launches "Health Up" Insurance Plan to Foster a Wellness Lifestyle for the Tech-savvy Generation

HONG KONG SAR - Media OutReach Newswire - 9 May 2025 - Chubb Life Hong Kong today announced the launch of Health Up Insurance Plan (Health Up), a digital insurance plan aimed at promoting and faci...

F88 officially becomes a public company, paving the way for UPCOM listing

HANOI, VIETNAM - Media OutReach Newswire - 8 May 2025 - On May 6, F88 Investment Joint Stock Company (F88) was officially recognised as a public company, marking a major milestone in its growth an...

UNSW startup accelerator offers $200K to the next generation of Australian deeptech unicorns

UNSW Founders, Australia’s most recommended startup accelerator, has partnered with fund manager Luminary Partners to invest $200,000 each into 18...

The Future Is Now: AI Modernization Is Reshaping How Business Gets Done

The present business environment imposes stronger requirements on Australian organizations to match the fast-paced digital-first economy requireme...

Businesses losing an average of $493k from data integrity flaws

Managing data responsibly and effectively for the AI age can give organisations a strong competitive advantage, but many are failing to harness th...

AI shopping disruptor Zyft raises $7.5M to lead the next gen of retail tech

Zyft appoints new CEO, Richard Stevens, to lead the latest Waller Group success story, valued at $30 million SYDNEY, 28 April 2025: Zyft, the lea...

Little known law offers savvy Kiwis the opportunity to supercharge their retirement savings

A little-known legal amendment is being leveraged by savvy New Zealanders and expat Brits to supercharge their retirement savings. Not many peop...

Cutting edge AI technology designed for doctors to reduce patient wait times launched in NZ

New Zealand specialist doctors now have access to Artificial Intelligence technology to help reduce patient wait times and experts say it could be...

Sell by LayBy