Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

HYPE Reaches New All-Time Highs Above $70 – A Legendary Trade Turns Green

June 2, 2026

Bitdeer Launches Liquid-Cooled SEALMINER DL1 Hydro for Litecoin and Dogecoin Mining

June 2, 2026

0.1% levy could raise €3B–€4B a year

June 2, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Elasticsearch Crypto-Miner Sinkholes the Competition
Elasticsearch Crypto-Miner Sinkholes the Competition
Security and Privacy

Elasticsearch Crypto-Miner Sinkholes the Competition

August 10, 2023No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Researchers have discovered a new crypto-mining campaign targeting Elasticsearch instances which contains sinkholing capabilities to squash any competing miners.

The aptly named “CryptoSink” malware campaign exploits an Elasticsearch vulnerability from 2014 (CVE-2014-3120) to mine cryptocurrency in Windows and Linux environments, according to F5’s Andrey Shalnev and Maxim Zavodchik.

At the time of the research, just one of the three hard-coded C&C domains was operational, resolving to a server located in China.

However, most interesting was the way it finds and kills any competing crypto-mining malware on the same host.

Typically, attackers do this by scanning running processes to find known malware names, or else looking to see which processes are consuming the most CPU.

“In this case, the malware dropper introduces a more sophisticated tactic to paralyze competitors who survive the initial purge. We’ve called it ‘CryptoSink’ because it sinkholes the outgoing traffic that is normally directed at popular cryptocurrency pools and redirects it to localhost (127.0.0.1) instead,” F5 explained.

“It achieves this by writing the target pools’ domains to the ‘/etc/hosts’ file. In doing so, the competitors’ miners are not able to connect to those cryptocurrency pools and fail to start the mining process, which frees up system resources on the infected machine.”

The malware has another trick up its sleeve, this time to achieve persistence. It renames the original rm binary relating to the Linux “remove” command, to “rmm” and replaces it with a malicious file named “rm”, downloaded from its C&C server.

“Now, each time the user executes the rm command, the forged rm file will randomly decide if it should additionally execute a malicious code, and only then will it call the real rm command (that is, execute the file now that’s now named rmm). The malicious code in the rm binary will check if the cronjob exists and if not, it will be added again,” F5 explained.

See also  UK to introduce comprehensive crypto regulations in 2025 as global competition heats up

“The irony is that even if the infected server’s administrator were to detect the other malicious files and try to remove them, she would probably use the rm command which, in turn, would reinstall the malware.”

Source link

Competition Cryptominer Elasticsearch Sinkholes
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Stake DAO Freezes Arbitrum vsdCRV Markets After Attacker Mints 5.4T Synthetic Tokens

May 29, 2026

Certik Unveils ‘Anti-Virus for AI Agents’ as Skill Marketplaces Face Hidden Threats

May 29, 2026

New Threat Actor Jinx-0164 Targets Crypto Developers on macOS

May 28, 2026

PureLogs Variant Steals Data via Purchase Order Lures

May 27, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Ethereum’s Dencun upgrade gets a new touch — Here’s how

September 30, 2023

Bitfarms Stock Rallied 72.86% Last Week – Time to Re-Rate?

September 21, 2025

Bitcoin miner Hut 8 secures 205MW site in Texas to upgrade its capacity to 1.3GW

July 9, 2024

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

HYPE Reaches New All-Time Highs Above $70 – A Legendary Trade Turns Green

June 2, 2026

Bitdeer Launches Liquid-Cooled SEALMINER DL1 Hydro for Litecoin and Dogecoin Mining

June 2, 2026

0.1% levy could raise €3B–€4B a year

June 2, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$70,650.00-4.12%
  • ethereumEthereum(ETH)$1,989.59-0.96%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$689.98-2.33%
  • rippleXRP(XRP)$1.28-3.75%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$80.31-2.78%
  • tronTRON(TRX)$0.342650-2.14%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.042.12%
  • HyperliquidHyperliquid(HYPE)$74.343.04%