The team at blogging platform Ghost have successfully defended against a major cryptojacking attack.
According to an official announcement, the developers at Ghost sprung into action as soon as the attack was detected in the early hours of 3 May, and within 4 hours had successfully implemented a fix.
Ghost says the incident involved attackers targeting its “Salt” server backend infrastructure, using authentication bypass and directory traversal, in an attempt to hijack control of the master server.
The platform says its development team noticed the attack as the hackers attempted to mine cryptocurrency using the platform servers, causing CPUs to spike and overload. Ghost has stressed that no sensitive information, such as user credit card details, had been affected, and no such information is stored in plaintext.
Apparently all traces of the crypto-mining virus have now been removed from the platform, but developers are continuing to “clean and rebuild” the entire network, cycling all sessions, passwords and keys, and re-provisioning all servers, as a precautionary measure.
AYO.NEWS says:
Cryptojacking has become less of a problem as the fall in crypto prices over the past year has made it less attractive to crooks (even prompting Coinhive to shut down). But, although we aren’t at the levels of early 2019, when according to SonicWall there were an incredible 52.7 million cryptojacking hits, a sizable problem still exists. Illustrating this, information from Guardicore Labs suggests up to 50K servers around the world have recently been infected with cryptojacking malware to mine privacy altcoin Turtlecoin (TRTL).
‘AYO.NEWS says’ features the opinion of the author and does not necessarily reflect the views of Pentagon Digital Limited or its affiliates or associates.
All original content featured on this site is © Pentagon Digital Limited, 2020.