• Home
  • Privacy Policy
  • Terms and Conditions
  • DMCA
  • Disclaimer
  • Contact us
Monday, June 23, 2025
No Result
View All Result
NEWSLETTER defal
Lebanon Hub
NEWSLETTER
  • Home – Lebanon hub
    • About us
    • Radio & Live Hosting
      • Home
      • Podcast
      • About us
      • Contact us
  • Blog
    • Submit Blog
  • News
    • International
      • Lebanon
      • Australia
      • Sports
      • Tech
      • Cyber Security
      • Music
      • Celebrity
      • TV
      • Movies
    • Gaming
      • Reviews
      • XBOX
      • PlayStation
      • PC
      • Mobile
      • New Released
      • Popular
    • Cryptocurrency
      • Blockchain
      • Bitcoin
      • Altcoin
      • Exchange
      • Startups
      • Ethereum
      • Litecoin
  • Business
    • Business Dashboard
    • Add New Business
  • Events
    • Event Dashboard
  • Apply Job
    • All Jobs
    • All Resumes
  • Contact us
  • Sign in
  • Sign up
  • Home – Lebanon hub
    • About us
    • Radio & Live Hosting
      • Home
      • Podcast
      • About us
      • Contact us
  • Blog
    • Submit Blog
  • News
    • International
      • Lebanon
      • Australia
      • Sports
      • Tech
      • Cyber Security
      • Music
      • Celebrity
      • TV
      • Movies
    • Gaming
      • Reviews
      • XBOX
      • PlayStation
      • PC
      • Mobile
      • New Released
      • Popular
    • Cryptocurrency
      • Blockchain
      • Bitcoin
      • Altcoin
      • Exchange
      • Startups
      • Ethereum
      • Litecoin
  • Business
    • Business Dashboard
    • Add New Business
  • Events
    • Event Dashboard
  • Apply Job
    • All Jobs
    • All Resumes
  • Contact us
  • Sign in
  • Sign up
No Result
View All Result
Lebanon Hub
No Result
View All Result

Attacker Targets Hadoop YARN, Flint Servers in Stealthy Campaign

January 11, 2024
in Cyber Security
0
Home Cyber Security
0
VIEWS
Share on FacebookShare on Twitter


A menace actor is focusing on a standard misconfiguration in Hadoop YARN and Apache Flink to try to drop Monero cyrptominers in environments operating the 2 large knowledge applied sciences.

What makes the marketing campaign particularly notable is the adversary’s use of subtle evasion strategies, comparable to rootkits, packed ELF binaries, listing content material deletion, and system configuration modifications to bypass typical menace detection mechanisms.

Recognized Misconfigurations

Researchers from Aqua Nautilus uncovered the marketing campaign after they noticed new assaults hitting one in every of their cloud honeypots not too long ago. One assault exploited a recognized misconfiguration in a function in Hadoop YARN referred to as ResourceManager that manages assets for purposes operating on a Hadoop cluster. The opposite focused a equally recognized misconfiguration in Flink that, just like the YARN concern, offers attackers a strategy to run arbitrary code on affected methods.

Hadoop YARN (But One other Useful resource Negotiator) is a useful resource administration subsystem of the Hadoop ecosystem for giant knowledge processing. Apache Flink is a comparatively extensively used open supply stream and batch processor for event-driven knowledge analytics and knowledge pipeline purposes.

Assaf Morag, lead researcher for Aqua Nautilus, says the YARN misconfiguration offers attackers a strategy to ship an unauthenticated API request to create new purposes. The Flink misconfiguration permits an attacker to add a Java archive (JAR) file that comprises malicious code to a FLINK server.

“Each misconfigurations allow distant code execution, implying that an attacker might doubtlessly achieve full management over the server,” Morag says. On condition that these servers are used for knowledge processing, their misconfigurations current an information exfiltration threat. “Moreover, these servers are sometimes interconnected with different servers inside the group, which might facilitate lateral motion by the attacker,” Morag says.

Deploying a Cryptominer

Within the assault on Apache Nautilus’ honeypots, the adversary exploited the misconfiguration in Hadoop YARN to ship an unauthenticated request to deploy a brand new utility. The attacker was then in a position to execute distant code on the misconfigured YARN by sending a POST request, asking it to launch the brand new utility utilizing the attacker’s command. To ascertain persistence, the attacker first deleted all cron jobs — or scheduled duties — on the YARN server and created a brand new cron job.

Aqua’s evaluation of the assault chain confirmed the attacker utilizing the command to delete the content material of the /tmp listing on the YARN server, downloading a malicious file to the /tmp listing from a distant command-and-control server, executing the file, after which once more deleting the contents of the listing. Aqua researchers discovered the secondary payload from the C2 server to be a packed ELF (Executable and Linkable Format) binary that served as a downloader for 2 totally different rootkits, one in every of which was a Monero crypto-currency miner. Malware detection engines on Virus Whole didn’t detect the secondary ELF binary payload, Aqua stated.

“As these servers are designed for processing large knowledge, they possess excessive CPU capabilities,” Morag says. “The attacker is exploiting this truth to run cryptominers, which additionally require a considerable quantity of CPU assets.”

Morag says the assault is noteworthy for the totally different strategies the attacker used to hide their malicious exercise. These included the usage of a packer to obfuscate the ELF binary, the usage of stripped payloads to make evaluation tougher, an embedded payload inside the ELF binary, file and listing permissions modifications, and the usage of two rootkits to cover the cryptominer and shell instructions.





Source link

Tags: AttackercampaignFlintHadoopserversStealthyTargetsYARN
Next Post
Finn raises 9M on a 8M valuation, taking its car subscription platform up another gear

Finn raises $109M on a $658M valuation, taking its car subscription platform up another gear

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Beirut, LB
14°
Cloudy / Wind
05:4017:50 EET
Feels like: 13°C
Wind: 34km/h SW
Humidity: 65%
Pressure: 1012.19mbar
UV index: 0
FriSatSun
14°C / 9°C
16°C / 11°C
18°C / 12°C
powered by Weather Atlas

Recent News

Grab Space Marine 2 and other Focus Entertainment games at up to 90% off

Grab Space Marine 2 and other Focus Entertainment games at up to 90% off

June 23, 2025
Neverwinter Nights 2’s new Switch 2 remaster is great for Baldur’s Gate 3 fans

Neverwinter Nights 2’s new Switch 2 remaster is great for Baldur’s Gate 3 fans

June 23, 2025
Minjee Lee wins Women’s PGA Championship, her third career golf major

Minjee Lee wins Women’s PGA Championship, her third career golf major

June 23, 2025
Germany and France win quarter-final epics

Germany and France win quarter-final epics

June 23, 2025
This major Kali Linux update could change how ethical hackers break into networks -new tools, VPN IP visibility, and more!

This major Kali Linux update could change how ethical hackers break into networks -new tools, VPN IP visibility, and more!

June 23, 2025
Should Bravo Finally Cut Jax Taylor from “The Valley?”

Should Bravo Finally Cut Jax Taylor from “The Valley?”

June 23, 2025
The 63 Best Shows on Amazon Prime Video Right Now

The 63 Best Shows on Amazon Prime Video Right Now

June 23, 2025
AC/DC Announces Homecoming Shows

AC/DC Announces Homecoming Shows

June 22, 2025
Lebanon Hub

Get the Latest Lebanon News and world News on LebanonHub.com. Local News, Sports, Technology, Music, Celebrity, Gaming News and Cryptocurrency Updates.

Category

  • Altcoin
  • Australia
  • Bitcoin
  • Blockchain
  • Celebrity
  • Cyber Security
  • Ethereum
  • Exchange
  • Litecoin
  • Local News
  • Mobile
  • Movies
  • Music
  • New Released
  • PC
  • PlayStation
  • Popular
  • Reviews
  • Sports
  • Startups
  • Technology
  • TV
  • XBOX

Recent News

Grab Space Marine 2 and other Focus Entertainment games at up to 90% off

Grab Space Marine 2 and other Focus Entertainment games at up to 90% off

June 23, 2025
Neverwinter Nights 2’s new Switch 2 remaster is great for Baldur’s Gate 3 fans

Neverwinter Nights 2’s new Switch 2 remaster is great for Baldur’s Gate 3 fans

June 23, 2025
  • Home
  • DMCA
  • Disclaimer
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2022 - Lebanon Hub.

No Result
View All Result
  • Home – Lebanon hub
    • About us
    • Radio & Live Hosting
      • Home
      • Podcast
      • About us
      • Contact us
  • Blog
    • Submit Blog
  • News
    • International
      • Lebanon
      • Australia
      • Sports
      • Tech
      • Cyber Security
      • Music
      • Celebrity
      • TV
      • Movies
    • Gaming
      • Reviews
      • XBOX
      • PlayStation
      • PC
      • Mobile
      • New Released
      • Popular
    • Cryptocurrency
      • Blockchain
      • Bitcoin
      • Altcoin
      • Exchange
      • Startups
      • Ethereum
      • Litecoin
  • Business
    • Business Dashboard
    • Add New Business
  • Events
    • Event Dashboard
  • Apply Job
    • All Jobs
    • All Resumes
  • Contact us
  • Sign in
  • Sign up

Copyright © 2022 - Lebanon Hub.