Latest news about Bitcoin and all cryptocurrencies. Your daily crypto news habit.
Security firm RedLock reveals Tesla cryptojack, attackers using non-password protected software container to mine crypto.
Cloud security intelligence (CSI) firm RedLock has exposed a new case of cryptojacking targeting Teslaās Amazon Web Serviceās (AWS) software container, the RedLock blog reported yesterday, Feb. 20.
Hackers accessed Teslaās AWS access credentials by penetrating a non-password protected Kubernetes software container. The hackers then used the Kubernetes container to mine for cryptocurrencies, for an as of yet unknown amount of time.
RedLockās CSI team exposed a similar hack of AWS for Bitcoin (BTC) mining purposes at companies Aviva and GemaltŠ¾Ā in October of last year. These companies, like Tesla, did not have passwords for their admin consoles.
The Tesla hack was well disguised--the hackers didnāt use an already-known mining pool, but instead put in their own mining pool software than connected the malicious script to an āunlistedā endpoint, complicating the ability to detect any suspicious activity.
The hackers also kept their CPU usage low to prevent being spotted, and hid the mining poolās IP address behind free content delivery network CloudFlare, RedLock reports.
Tesla had already made the news last year for an innovative way to use their technologies to mine Bitcoin in a way completely unintended by the company. In December 2017, the owner of a Tesla S electric car reported that he had been mining Bitcoin with his carās supercharger, placing a mining rig in the trunk.
RedLockās blog post detailing the hack, titled, āLessons from the Cryptojacking Attack at Tesla,ā ends with suggestions to companies to prevent similar cryptojacking incidents in the future, namely monitoring configurations, network traffic, and suspicious user behavior.
And, as TechCruch adds, āat least [using] a password.ā
Disclaimer
The views and opinions expressed in this article are solely those of the authors and do not reflect the views of Bitcoin Insider. Every investment and trading move involves risk - this is especially true for cryptocurrencies given their volatility. We strongly advise our readers to conduct their own research when making a decision.