Skip to main content
  1. Home
  2. Computing
  3. News

Crypto-mining malware nets hacker group $3.4 million worth of Monero coins

Add as a preferred source on Google

Israeli security firm Check Point uncovered a large-scale cryptocurrency mining operation which installed malware on servers running Jenkins, an automation software designed for web development. The mining operation has, to date, mined around $3.4 million worth of Monero using malware installed on internet-connected Jenkins servers.

Unlike other illicit cryptocurrency mining operations, this one targeted servers rather than personal computers, which is why it went undetected long enough to earn some serious cash — $3.4 million as of this reporting.

Recommended Videos

The mining operation, which Check Point tracked to China, exploited a known vulnerability in Jenkins servers which allowed them to essentially ask the automation software to download and install the crypto-mining software. Jenkins, the ever-faithful automation software happily obliged.

Though this mining operation didn’t target personal computers, Check Point speculates that its presence on these Jenkins servers could still have some negative effects for everyday people.

“The JenkinsMiner could negatively impact the servers, causing slower load times and even issuing a Denial of Service. Depending on the strength of the attack, this could prove to be very detrimental to the machines,” Check Point reports.

While this kind of vulnerability might not be of concern to most people, it should definitely raise some eyebrows for web developers. It’s not the first time Jenkins servers have been exploited, and according to Bleeping Computer, exposed Jenkins servers pose a serious security risk to the web at large.

Citing research from security expert Mikail Tunç, Bleeping Computer reports that the researcher detected 25,000 exposed and vulnerable Jenkins servers as of mid-January. These servers are vulnerable not only because of the known exploits which hackers can use to turn them to their own ends but because of their connection to the internet. Insulating a Jenkins server from the web would be a big step in the right direction and keep hackers from repurposing a benign automation tool into a crypto-mining powerhouse.

This cryptocurrency mining operation is just one of many similar operations, siphoning clock cycles to mine Monero or other cryptocurrencies. According to Bleeping Computer, illicit Monero mining is already seeing an enormous uptick in 2018, with no signs of slowing down.

Why Monero? Well, Monero is an open-source cryptocurrency designed to be untraceable, private, and highly secure. Its security features make it an excellent choice for privacy-minded individuals, and sadly, illicit operations like this malicious mining operation.

Jaina Grey
Former Digital Trends Contributor
Jaina Grey is a Seattle-based journalist with over a decade of experience covering technology, coffee, gaming, and AI. Her…
Google’s Gemini app adds a toggle to disable AI watermarks, with some exceptions
Your AI creations no longer need a visible stamp.
nano banana

If you have ever generated an image with Gemini and gotten annoyed by that stamped-on watermark, Google finally heard you. Gemini is rolling out a new setting called Media Watermarks that lets you toggle visible watermarks on or off across everything you create, including images made with Nano Banana, videos made with Omni, and music made with Lyria. Until now, that visible watermark was applied automatically with no way to turn it off.

https://twitter.com/geminiapp/status/2088277477672255830?s=46

Read more
U.S. courts will now make government use of spyware tools public
U.S. courts will soon start putting numbers on government spyware use
landfall-spyware-hacker

U.S. courts are set to begin publicly reporting how often federal judges authorize the government to use spyware and hacking tools to intercept real-time communications, giving the public its first standardized view of how frequently these surveillance techniques are being used.

The change will begin with data collected for the 2028 Wiretap Report, which will be published in 2029. The Administrative Office of the U.S. Courts told TechCrunch that the report will introduce a new “spyware/hacking” category covering wiretaps conducted using hacking tools and spyware, known to federal authorities as network investigative techniques, or NITs.

Read more
Mark Rober’s new CrunchLabs mysteries turn reading into a hands-on STEM adventure
Rober is expanding CrunchLabs with a series of mystery books focus on improving STEM skills with a fun twist.
Book, Publication, Comics

Mark Rober has spent years proving that science and engineering don’t have to feel like homework. His enormously popular videos turn subjects such as physics, robotics, and mechanical engineering into spectacular challenges, ingenious pranks, and machines that kids immediately want to understand.

CrunchLabs has carried that approach into the physical world with its Build Box subscriptions. Now Rober is taking it in another direction: children’s fiction.

Read more