AdguardTeam / AdguardFilters

AdGuard Content Blocking Filters
https://adguard.com/
GNU General Public License v3.0
2.92k stars 613 forks source link

Cado Labs researchers recently discovered a novel cryptojacking campaign targeting insecure deployments of Redis #144404

Closed ghost closed 1 year ago

ghost commented 1 year ago

Prerequisites

Problem description

There was a recent discovery into a new cryptojacking campaign by Cado Labs which identifies a range of new mining pools to add to the AdGuard Base filter cryptominers filter.

A custom XMRig configuration is written to disk, which registers the miner with the following mining pools:

xmr.pool.gntl.co.uk pool.hashvault.pro xmr-eu1.nanopool.org monerohash.com pool.supportxmr.com ca.monero.herominers.com xmrpool.eu pool.xmrfast.com pool.xmr.pt

Proposed solution

Block the above in the AdGuard Base cryptominers filter.

Additional information

https://www.cadosecurity.com/redis-miner-leverages-command-line-file-hosting-service/

Alex-302 commented 1 year ago

Why mining pools must be blocked?

ghost commented 1 year ago

The article under additional information explains it.

In short, those are the mining pools used by the exploit which are written to a config after the vulnerable Redis distribution is prepared.

Alex-302 commented 1 year ago

This is not a reason to block public pools. Those who have been infected are not likely using our DNS)