Hackers Target PostgreSQL DBs With Coinminer Hidden in Scarlett Johannsson Image

Faybert

Level 24
Thread author
Verified
Top Poster
Well-known
Jan 8, 2017
1,318
A new type of attack has been discovered targeting PostgreSQL databases, in which malware authors are using an image of Hollywood actress Scarlett Johansson to hide a cryptocurrency miner they intend to run on the DB's underlying server.

The attack has been observed in a honeypot server ran by Imperva researchers. Experts say crooks gained access to a PostgreSQL database user account, where they executed payloads found in the Metasploit framework's PostgreSQL module.
....
....
Coinminer hidden in benign PNG image
Once attackers escalate their access, the first series of commands they run (listing the server's CPU and GPU details) reveal their true intentions —cryptocurrency mining.

Hackers will then download a PNG file (art-981754.png) from a legitimate image hosting service —imagehousing.com. Researchers say this image (embedded below) portrays famous Hollywood actress Scarlett Johansson, at first glance, but when they looked at the image's binary code, they found a cryptocurrency miner appended after the actual image data.
.....
.....
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top