In a significant discovery, cybersecurity researchers have developed the first completely undetectable cloud-based cryptocurrency miner using Microsoft's Azure Automation service without incurring any costs. SafeBreach, a cybersecurity company, identified three methods to execute this miner, including one capable of running in a victim's environment without raising suspicions. The objective was to create the "ultimate crypto miner" that offers unlimited access to computational resources, requires minimal maintenance, is cost-free, and remains undetectable. Microsoft's Azure Automation service played a crucial role in achieving this feat. One method involved exploiting a bug in the Azure pricing calculator, allowing the execution of an unlimited number of jobs within the attacker's environment without incurring charges. Microsoft has since addressed and fixed this issue. Another approach included creating a test job for mining, marking it as "Failed," and leveraging the limitation of one test job running at a time to effectively conceal code execution within the Azure environment. Threat actors could utilize these techniques to establish a reverse shell toward an external server and authenticate to the Automation endpoint to achieve their objectives. Furthermore, researchers discovered that code execution could be achieved by uploading custom Python packages within Azure Automation, potentially opening doors for various malicious activities. Microsoft, in response, labeled the behavior "by design," indicating it can still be exploited without incurring charges. While the study primarily focused on cryptocurrency mining abuse within Azure Automation, SafeBreach cautioned that threat actors could repurpose these techniques for any task requiring code execution on Azure. Organizations utilizing cloud services must proactively monitor all resources and actions within their environment to mitigate such risks.
The Proto6 disclosure highlights a set of security flaws within protobuf.js that can be abused when applications process untrusted Protocol Buffer content. The vulnerabilities stem...
Security researchers have uncovered a malware distribution campaign in which threat actors leverage fake utility software downloads to infect users with malicious payloads. The ope...
Researchers have reported a significant increase in activity associated with the JDY botnet, a malware network previously linked to Chinese cyber threat groups, including those con...