Trend Micro report warns of growing attack surface for CPU-mining
HONG KONG SAR –
Media OutReach – 30 March 2022 –
Trend Micro Incorporated (
TYO: 4704;
TSE: 4704), a global cybersecurity leader, today announced a new report revealing a fierce, hour-by-hour battle for resources among malicious cryptocurrency mining groups.
To read the
“A Floating Battleground Navigating the Landscape of Cloud-Based Cryptocurrency Mining” report:
https://www.trendmicro.com/vinfo/hk/security/news/cybercrime-and-digital-threats/probing-the-activities-of-cloud-based-cryptocurrency-mining-groups “Just a few hours of compromise could result in profits for the perpetrators. That’s why we’re seeing a continuous fight for cloud CPU resources. It’s akin to a real-life capture-the-flag, with the victim’s cloud infrastructure the battleground,” said Stephen Hilt, Senior Threat Researcher at Trend Micro. “Threats like this need joined-up, platform-based security to ensure the bad guys have nowhere to hide. The right platform will help teams map their attack surface, assess risk, and apply for the right protection without adding excessive overheads.”
Threat actors are increasingly scanning for and exploiting these exposed instances, as well as brute-forcing SecureShell (SSH) credentials, in order to compromise cloud assets for cryptocurrency mining, the report reveals. Targets are often characterized by having outdated cloud software in the cloud environment, poor cloud security hygiene, or inadequate knowledge on how to secure cloud services and thus easily exploited by threat actors to gain access to the systems.
Cloud computing investments have surged during the pandemic. But the ease with which new assets can be deployed has also left many cloud instances online for longer than needed—unpatched and misconfigured.
On one hand, this extra computing workload threatens to slow key user-facing services for victim organizations, as well as increasing operating costs by up to 600% for every infected system.
Crypto mining can also be a precursor to more serious compromise. Many mature threat actors deploy mining software to generate additional revenue before online buyers purchase access for ransomware, data theft, and more.
The Trend Micro report details the activity of multiple threat actor groups in this space, including:
Outlaw, which compromises IoT devices and Linux cloud servers by exploiting known vulnerabilities or performing brute-force SSH attacks.
TeamTNT, which exploits vulnerable software to compromise hosts before stealing credentials for other services to help it move around to new hosts and abuse any misconfigured services.
Kinsing, which sets up an XMRig kit for mining Monero and kicks any other miners off a victim system.
8220, which has been observed fighting Kinsing over the same resources. They frequently eject each other from a host and then install their own cryptocurrency miners.
Kek Security, which has been associated with IoT malware and running botnet services.
To mitigate the threat from cryptocurrency mining attacks in the cloud, Trend Micro recommends organizations to:
- Ensure systems are up-to-date and running only the required services
- Deploy firewall, IDS/IPS, and cloud endpoint security to limit and filter network traffic to and from known bad hosts
- Eliminate configuration errors via Cloud Security Posture Management tools
- Monitor traffic to and from cloud instances and filter out domains associated with known mining pools
- Deploy rules that monitor open ports, changes to DNS routing, and utilization of CPU resources from a cost perspective
About Trend Micro
Trend Micro, a global cybersecurity leader, helps make the world safe for exchanging digital information. Fueled by decades of security expertise, global threat research, and continuous innovation, Trend Micro’s cybersecurity platform protects hundreds of thousands of organizations and millions of individuals across clouds, networks, devices, and endpoints. As a leader in cloud and enterprise cybersecurity, the platform delivers a powerful range of advanced threat defense techniques optimized for environments like AWS, Microsoft, and Google, and central visibility for better, faster detection and response. With 7,000 employees across 65 countries, Trend Micro enables organizations to simplify and secure their connected world. www.trendmicro.com.hk
#TrendMicro
Services
Stakeholder mapping, analysis, engagement and communication needs to be detailed to avoid business losses or even worse, a crisis. How can you do this effectively to prevent failure? ...
Data-driven business decisions have never been as crucial, especially in this era. MGBF leverages off, technology, experience and market presence to aid businesses in making accurate decisions. ...
MGBF provides comprehensive strategic advice and results-focused solutions to solve clients' problems in business-government relations so they can focus on their core business. ...
A critical business challenge is meeting the right decision-makers and potential buyers through the best channel and platform. How will you improve your business competency? ...
Upcoming Events
In this episode of 'A Working Lunch with Nordin', MGBF's Nordin Abdullah and regional commentator Eddin Khoo will discuss the biggest threats and opportunities for businesses as we look to manage change in the South China Sea.
This MGBF Roundtable will feature thought leaders form Japan, Australia, Singapore and Malaysia dealing with the critical issues of manipulation of public listed companies and government and their financial impacts.
A series of networking sessions with various business associations and trade organisations exploring high-value opportunities for business leaders and entrepreneurs looking to build the relationships that matter.
This integrated event will include a forum, dedicated business matching, site visits, a gala dinner and a round of golf. Aptly themed, the focus will be on regional food security issues and trends in the context of the supply chain, agriculture technology and trade regulations and policies.
MGBF In The News
Planet QEOS and China Machinery Engineering Corporation (CMEC) are interested in investing RM10 billion to co-develop advanced Megawatt peak (MWp) agrovoltaic in Baram, to further boost Sarawak’s green energy initiative and food security. Sarawak Premier Datuk Patinggi Tan Sri Abang Johari Tun Openg was briefed on Friday by both the […]
Last week SPM results came out, 373,974 aspirants who have been waiting patiently over the last few months would now know their fate. Some 10,109 have received all A’s, the golden standard of academic success and the ticket to those looking to study the “more advanced” subjects in university. Proudly, […]
The classic knee-jerk reaction is to say, fire the coach, change the leadership of associations, and reduce the funding till they start performing better. This kind of negative reinforcement may work for kindergarten children, but we are dealing with high-performance adults – individuals much further along in their psychological and […]
Since its earliest tea plantations in 1929, Cameron Highlands has grown to become a key player in the agricultural landscape of Malaysia, producing 40 per cent of all vegetables grown. Despite Malaysia shifting its economic focus away from agriculture, the industry remains imperative for food security and the livelihoods of […]
Although at first glance the travel industry and the agricultural sector appear to have nothing in common, they actually share more than meets the eye. The economic benefits of tourism to the agricultural sector can be multiplied several times over. “Tourism brings the end consumers closer to the source, which […]
The Malaysia Global Business Forum (MGBF) recently held a high-level roundtable themed ‘Designing the Future of the Digital Economy’, attended by industry leaders and business associations. The guest of honour was Yang Berhormat Syerleena Abdul Rashid, the Member of Parliament (MP) for Bukit Bendera in Penang. The MP’s Special Session […]
The Malaysia Global Business Forum (MGBF) will be hosting a roundtable on ‘Designing the Future of the Digital Economy’ on 23 February 2023. It is the culmination of the first three MGBF Exclusive Roundtable Series titled ‘The Evolving Threat Matrix in the Digital Economy’ held throughout 2022. According to the […]
The Founding Chairman of the Malaysia Global Business Forum (MGBF), Nordin Abdullah, today spoke on Bernama TV’s leading English talk show, The Brief, hosted by Jessy Chahal, on the topic of a stable political reality and what that means for the Malaysian economy. Nordin said, “The first thing that it […]
More than 1,100 years ago, Muhammad ibn Musa al-Khwarizmi was developing the mathematical formulas that we know today as algorithms which now have become so intertwined with the business fortunes of global media giants and the very fabric of geopolitics. A series of recent high level international reports have revealed […]
KSK Land has been recognised by the Malaysia Global Business Forum (MGBF) for its role in attracting high net-worth individuals to Malaysia post-pandemic. The first challenge in investor attraction is “selling” the country. In the context of Asia, Malaysia is competing with some very established investment destinations. The second […]
Malaysia, in particular Kuala Lumpur, continues to position itself as a regional centre to do business, educate a family and enjoy a global lifestyle. One company, KSK Land, has taken the lead in positioning itself and the city of Kuala Lumpur as a property investment destination for the global citizen […]
The upcoming budget represents an opportunity to build resilience in the critical sectors that will form the backbone of the country’s future-facing economic ambitions. This however needs to be achieved in the context of managing the community sectors most impacted by COVID-19 over the past two years. The Keluarga Malaysia (Malaysian Family) […]
Malaysia Global Business Forum (MGBF) has moved to support the creative economy as the overall economy moves into a recovery phase following the COVID19 pandemic. As a step in the direction of normalcy, the MGBF has agreed to host the art exhibition “I Know You’re Somewhere So Far” by one […]
Congratulations to Datuk Seri Ismail Sabri Yaakob for taking up the mantle of the ninth prime minister of Malaysia. There is nothing normal about the situation; it could not have been scripted but it has kept the spectrum of media, mainstream and social, gripped. The first order of business for […]
In a stirring speech to the nation, President Joseph R. Biden, Jr. stamped his brand of leadership on the presidency, in his first act as the 46th president of the United State of America, it signaled several shifts. Perhaps the weather was foreboding with snow falling before the ceremony that […]
KUALA LUMPUR, 6 July 2022 – As the global economy continues to deal with unprecedented levels of disruption caused by the pandemic and the conflict between Russia and Ukraine, the convergence of energy security and food security issues has become a front-of-mind issue faced by policy makers and consumers alike. […]
KUALA LUMPUR, 23 June 2022 — Malaysia Global Business Forum (MGBF) ties up with scoutAsia to ensure that businesses are equipped with deeper regional insights. The past two years has seen a massive shift in the way businesses are conducted with digitisation, digitalisation and automation continuously being adopted to improve […]
KUALA LUMPUR, 25 May 2022 – The Malaysia Global Business Forum (MGBF)’s exclusive roundtable on ‘Security Concerns in Critical Value Chains’ was held in a hybrid setting yesterday at the Eastin Hotel Kuala Lumpur. The guest of honour was Yang Berbahagia Tan Sri Dato’ Seri Rafidah Aziz, former minister of […]
We live in the age of crisis. At the heart of any crisis is the threat of rapid change. Change too deep or too wide that the current coping mechanisms for an individual, corporation or government are unable to remain resilient. An unwelcome paradigm shift, like the proverbial spider, that […]