Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

Here is why Strategy's dividend-paying crypto stock is crashing to near-historic lows

June 16, 2026

HashKey Chain Partners Morpho to Blend Compliance and DeFi for Institutional CeDeFi and RWA Lending

June 16, 2026

Kraken Brings Regulated Perpetual Futures Onshore to US Users

June 16, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»Proxyjacking and Cryptomining Campaign Targets GitLab
Proxyjacking and Cryptomining Campaign Targets GitLab
Security

Proxyjacking and Cryptomining Campaign Targets GitLab

September 24, 2023No Comments2 Mins Read

Security researchers have discovered a new financially motivated cyber-threat campaign designed to make money from cryptomining and proxyjacking while staying hidden using a variety of techniques.

The Labrat campaign was discovered by a team at Sysdig, who observed the threat actors compromise a targeted container via legacy GitLab remote code execution vulnerability CVE-2021-22205.

The end goal is to make money by cryptomining and proxyjacking; the latter being attacks where threat actors rent out a compromised system to a proxy network.

To maintain this revenue stream, the threat group are going to extreme lengths to stay hidden from researchers and network defenders, Sysdig claimed.

“It is common to see attackers utilize scripts as their malware because they are simpler to create. However, this attacker chose to use undetected compiled binaries, written in Go and .NET, which allowed the attacker to hide more effectively,” the security vendor explained.

“Furthermore, the attacker abused a legitimate service, TryCloudFlare, to obfuscate their C2 network.”

Read more on stealthy crypto attacks: Satacom Malware Campaign Steals Crypto Via Stealthy Browser Extension

Moreover, the attackers are constantly updating their binaries in order to avoid detection, Sysdig claimed.

To maintain persistence, the Labrat attackers use a legitimate open-source tool known as Global Socket (GSocket).

“Much like Netcat, GSocket has legitimate uses, but of course it can also be used by attackers,” Sysdig wrote.

“Unlike Netcat, GSocket provides features such as a custom relay or proxy network, encryption, and the ability to use TOR, making it a very capable tool for stealthy C2 communications. To remove evidence of its installation, the LABRAT attacker tried to hide the process.”

See also  Hyperbridge relaunches with decentralized overhaul after April exploit

The campaign is ongoing and may even be designed to go beyond proxyjacking and cryptomining, given that the backdoor used provides access to compromised systems, the research team concluded.

“Users impacted by CVE-2021-22205 should follow their organization’s security incident and disaster recovery processes to deprovision the compromised instance and restore the latest good working backup to a new GitLab instance,” noted a GitLab statement sent to Infosecurity.

“The vulnerability has been patched since 2021 and the impact is on customers who remain on vulnerable versions. We issued a blog post regarding the vulnerability and a forum post about how users can determine if they have been impacted.”

Editorial image credit: T. Schneider / Shutterstock.com

Source link

Campaign Cryptomining GitLab Proxyjacking Targets

Related Posts

India’s NHRC Raises Alarm Over Digital Arrest Scams

June 16, 2026

Rokarolla Trojan Combines Banking Fraud With Device Surveillance

June 16, 2026

Pyra to Cease Operations Following Drift Hack, Launches Fund Withdrawal Portal

June 16, 2026

Oklahoma Raises Alarm Over Fake Crypto Returns

June 16, 2026
Top Posts

The Growing Differences Between Competitive and Casual Gaming Audiences

April 21, 2026

Transit Finance hack drains $1.88M from cross-chain protocol

May 15, 2026

New South Wales Police seize 52.3 Bitcoin worth $4.2M from darknet operator

May 11, 2026

Type above and press Enter to search. Press Esc to cancel.