Hackers can use compromised Google Cloud accounts to install mining software in under 30 seconds: Report

Hackers can use compromised Google Cloud accounts to install mining software in under 30 seconds: Report

In a report aimed at assessing threats to Cloud users, Google’s Cybersecurity Action Team said that some attackers are exploiting “poorly configured” accounts to mine cryptocurrency.

On Wednesday, the Google team said out of 50 analyzed incidents that compromised the Google Cloud Protocol, 86% were related to crypto mining. The hackers used the compromised Cloud accounts to access resources from individuals’ CPUs or GPUs to mine tokens or take advantage of storage space when mining coins on the Chia Network.

Our top trading bots

However, Google’s team reported that many of the attacks were not limited to a single malicious action like crypto mining, but were also staging points to conduct other hacks and identify other vulnerable systems. According to the cybersecurity team, the actors usually gained access to Cloud accounts as a result of “poor customer security practices” or “vulnerable third-party software.”

“While data theft did not appear to be the objective of these compromises, it remains a risk associated with the Cloud asset compromises as bad actors start performing multiple forms of abuse,” said the Cybersecurity Action Team. “The public Internet-facing Cloud instances were open to scanning and brute force attacks.”

The speed of the attacks was also noteworthy. According to Google’s analysis, hackers were able to download crypto mining software to the compromised accounts within 22 seconds in the majority of the incidents analyzed. Google suggested that “the initial attacks and subsequent downloads were scripted events not requiring human intervention” and said it would be nearly impossible to manually intervene to stop such incidents once they started.

Related: Google bans 8 'deceptive' crypto apps from Play Store

An attack on multiple users’ Cloud accounts to gain access to additional computing power is not a new approach to illicitly mining crypto. "Cryptojacking," as it is known by many in the space, has had several high-profile incidents including a hack of Capital One in 2019 to allegedly use credit card users’ servers to mine crypto. However, browser-based cryptojacking as well as mining crypto after gaining access through deceptive app downloads is also still a problem for many users.

Continue reading upon Cointelegraph
Blockchain play-and-earn games focus on building even as NFT prices fall
Nonfungible tokens (NFTs) were in a strong bull run from Jan. 1 to mid-February. During this time, OpenSea volumes topped $5 billion and then fell to $3.6...
Scan your dog and go walkies in the Metaverse: Virtual NFT pets get popular
New research suggests that during the height of COVID-19, the number of people searching for a furry friend to keep them company hit new highs – not only...
Bank of Russia to allow crypto investment via foreign firms: Report
Russia continues sending mixed signals to the cryptocurrency markets as more reports provide details on the country’s upcoming crypto regulation.Shortly...
SHIB, RGT and AMPL shake off Fed taper comments by notching double-digit gains
Volatility reared its ugly head for a second day after growing fear of the new Omicron COVID-19 variant and the Federal Reserve's admission that an earlier-than-expected...
Bitcoin price metric demands ‘strong reaction’ as $56K BTC starts to look ‘seriously cheap’
Bitcoin (BTC) is “seriously cheap” at $56,000 relative to network activity — and that means only one thing, one analyst says.In a tweet on Nov. 24, Philip...
Fresh Bitcoin price highs put bulls in profit for Friday’s $1.2B BTC options expiry
Every time a new Bitcoin (BTC) all-time high is formed, excessive expectations follow. This time was no different as its price briefly touched $69,000 in...
Pakistani blockchain marketplace completes record $30M raise
Pakistani blockchain-powered business-to-business (B2B) marketplace, Bazaar Technologies, has secured $30 million in the country’s largest Series A round...
Blockchain-based digital art installation to launch on Vancouver bridge
Canadian public art exhibition organization Vancouver Biennale is preparing to unveil an art installation that combines physical and digital realities with...
Blockchain identity market to grow $3.58B by 2025, report claims
A new report on the potential for blockchain identity management solutions to become integrated across sectors has forecast strong growth for its global...
Top 5 cryptocurrencies to watch this week: BTC, ETH, UNI, ICP, AAVE
In a recent CNBC survey of a group of portfolio managers and equity strategists, only 6% of respondents expect Bitcoin (BTC) to reach $60,000 in 2021. A...
Data shows derivatives had little to do with Bitcoin's drop to $29K
After a brief recovery to $41,000 on June 14, Bitcoin (BTC) investors might have thought that the bear market was finally over. After all, it was the highest...
As Yearn.Finance’s yield vaults grow, ‘crop’ projects define boundaries
With millions and even billions of dollars at stake, industrial-scale yield farming is leading to pockets of resistance as some projects refuse to be left...
Coinbase to acquire Skew crypto data analytics platform
United States cryptocurrency giant Coinbase is acquiring institutional-grade blockchain data analytics platform Skew.Greg Tusar, vice president of institutional...
Lockheed Martin adopts blockchain for supply chain management in Switzerland
United States aerospace and defense contractor Lockheed Martin has signed an agreement with SyncFab, a Silicon Valley distributed manufacturing platform,...
Bakkt launches payments app as institutions compete for crypto assets
Major financial institutions are expanding their cryptocurrency services, with Bakkt launching its digital asset payments application for the general public.Bakkt...