Jenkins Vulnerability Mining
3 min read

The Massive Undercover Mining Operation you Have Never Heard About

By Editorial Team

One of the biggest cryptocurrency mining operations has just been discovered. Spanning across the globe to numerous computers, the miners have been able to generate a hefty $3.4m in revenue.

The mining operation in question is actually an exploitation by a hacker. The threat actor made use of a critical vulnerability in Jenkins servers to install software that mines Monero, the privacy conscious cryptocurrency.

The existence of the mining operation was first discovered by researchers at check point research. Apart from giving the operator a great deal of elicit XMR, the attack will also slow the servers and possibly also issue a Denial of Service (DoS) attack.

Let's take a deeper look into this anonymous miner.

Critical Vulnerabilities

Unlike many other Monero mining exploits that make use of malware and compromised websites, the Jenkins exploit makes use of a critical vulnerability. These are also termed zero day exploits.

The undercover miner has been operating for the past 18 months and has previously made use of Windows vulnerabilities. They used these vulnerabilities to remotely download Monero mining software that would operate in the background.

Hijacking the processing power of these Windows machines was able to generate the miner 10,829 XMR which is just over $3m. The hacker, which the researchers claim is of “Chinese origin” has now moved on to exploit the vulnerability in the Jenkins server.

The vulnerability in question exists on the Jenkins Continuous Integration m(JCI) server software. More technically known as CVE-2017-1000353, the vulnerability stems from the Java deserialization and a lack of object validation.

The hacker was able to exploit this vulnerability by sending carefully crafted requests to the server. He will also then include two main objects one of which will be the “command object”. The latter contains the miner payload which then executes PowerShell code.

Part XMRig Part RAT

The mining operation makes use of a hybrid version of the XMRig mining software and a Remote Access Trojan (RAT). The researchers claimed that although the miner can operate on several different machines, most of the victims appear to be personal computers. They also noted that

With every campaign, the malware has gone through several updates and the mining pool used to transfer the profits is also changed

The mining operation is also well managed and makes use of rotations to several different mining pools. However, most likely out of convenience the hacker makes use of only one Monero wallet. The wallet in question is in the below image with mining rewards still streaming in.

Monero Wallet Mining Jenkins
$3m Dollar Monero Waller. Source: checkpoint.com

Importance of Updates

The common thread in most of these exploits is that the vulnerabilities have been known. Much like the massive Wannacry attack last year with the Eternal blue exploits, the Jenkins vulnerability was known for some time.

When the vulnerability was made known by the developers, everyone should have updated their software immediately. However, out of convenience and lack of motivation, some developers left the vulnerability open.

If you want to make sure that your computing resources are not making someone else rich, update your software.

Featured Image via Fotolia

Editors at large. Posting the latest news, reviews and analysis to hit the blockchain.
View all posts by Editorial Team -> Best Crypto Deals ->

Related Posts

SwissBorg Capital Raise
What Bear Market? SwissBorg Charges Ahead Amidst Harsh Crypto Conditions 
SwissBorg Capital Raise

What Bear Market? SwissBorg Charges Ahead Amidst Harsh Crypto Conditions 

December 17, 2022 6 min read
OKX invests in WAX
OKX Blockdream Ventures Invests Millions in GameFi and NFT Development on WAX
OKX invests in WAX

OKX Blockdream Ventures Invests Millions in GameFi and NFT Development on WAX

June 3, 2022 2 min read
Binance partners with the weekend
Binance Partners with The Weekend to Provide First-Ever Web 3 Enhanced World Tour
Binance partners with the weekend

Binance Partners with The Weekend to Provide First-Ever Web 3 Enhanced World Tour

June 3, 2022 2 min read
21Shares Releases Sixth State of Crypto Report
21Shares Releases Sixth State of Crypto Report: Summary
21Shares Releases Sixth State of Crypto Report

21Shares Releases Sixth State of Crypto Report: Summary

April 5th, 2023 3 min read
Algorand and MakerX Commit 1M Algo to Migrate Terra Users to Algorand
Algorand and MakerX Commit 1M Algo to Migrate Terra Users to Algorand
Algorand and MakerX Commit 1M Algo to Migrate Terra Users to Algorand

Algorand and MakerX Commit 1M Algo to Migrate Terra Users to Algorand

June 2, 2022 2 min read
Regulators are “Not Allowing” Banks to Engage with Crypto
Bank of America CEO: Regulators are “Not Allowing” Banks to Engage with Crypto
Regulators are “Not Allowing” Banks to Engage with Crypto

Bank of America CEO: Regulators are “Not Allowing” Banks to Engage with Crypto

June 1, 2022 2 min read
US Conference of Mayors Introduces Blockchain Resolution
US Conference of Mayors Introduces Blockchain Resolution
US Conference of Mayors Introduces Blockchain Resolution

US Conference of Mayors Introduces Blockchain Resolution

June 1, 2022 2 min read