Cyber Bandwidth Bandits: Selenium Grid Servers Hijacked for Proxyjacking and Cryptomining

Selenium proxyjacking is on the rise as threat actors exploit Internet-exposed Selenium Grid servers. These servers, essential for automated web testing, are being hijacked for cryptomining and other malicious activities. Don’t let your bandwidth become a hacker’s playground!

Hot Take:

“Looks like your friendly neighborhood Selenium Grid is the latest star in the cybercriminal’s reality show. Today’s episode? Proxyjacking and cryptomining, coming to a server near you!”

Key Points:

  • Internet-exposed Selenium Grid servers are being hijacked for cryptomining and proxyjacking.
  • Selenium Grid is an open-source tool for browser automation, widely used in cloud environments and development.
  • Hackers deploy malware to hijack these servers, using tools like GSocket and payloads like Pawns.app and EarnFM.
  • More severe attacks involve using CVE-2021-4043 to escalate privileges and deploy cryptominers.
  • Over 30,000 Selenium Grid servers are publicly exposed, making them prime targets for cybercriminals.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here