Hackers exploit public DevOps tools for cryptocurrency mining attacks
2025-06-04 15:50
Odaily News Security company Wiz discovered that a hacker group codenamed JINX-0132 is using DevOps tool configuration vulnerabilities to conduct cryptocurrency mining attacks on a large scale. The attack mainly targets tools such as HashiCorp Nomad/Consul, Docker API, and Gitea, and about 25% of cloud environments are at risk. The attack methods include: using Nomad default configuration to deploy XMRig mining software, executing malicious scripts through Consul unauthorized API, and controlling the exposed Docker API to create mining containers. (The Register)
