Microsoft discovers cryptomining gang hijacking ML-focused Kubernetes clusters

kubeflow.png

Microsoft has published a report today detailing a never-before-seen series of attacks against Kubeflow, a toolkit for running machine learning (ML) operations on top of Kubernetes clusters.

The attacks have been going on since April this year, and Microsoft says its end-goal has been to install a cryptocurrency miner on Kubernetes clusters running Kubeflow instances exposed to the internet.

According to Yossi Weizman, a security researcher with Microsoft’s Azure Security Center, the company has detected these types of attacks against “tens of Kubernetes clusters” running Kubeflow.

But while the number of hijacked clusters is small in comparison to previous Kubernetes attacks, the profits for crooks and the financial losses to server owners are most likely much higher than other attacks seen before.

Coinbase 2

“Nodes that are used for ML tasks are often relatively powerful, and in some cases include GPUs,” Weizman explained.

“This fact makes Kubernetes clusters that are used for ML tasks a perfect target for crypto mining campaigns, which was the aim of this attack.”

Attacks began in April this year

Microsoft says it’s been tracking these attacks since April when it first saw them get underway and documented the first attack wave, before crooks expanded their focus from general-purpose Kubernetes instances to ML-focused clusters running Kubeflow.

As it learned more from its investigation into the early attacks, Microsoft now says it believes the most likely point of entry for the attacks are misconfigured Kubeflow instances.

In a report today, Microsoft said that Kubeflow admins most likely changed the Kubeflow default settings and exposed the toolkit’s admin panel on the internet. By default, the Kubeflow management panel is exposed only internally and accessible from inside the Kubernetes cluster.

misconfigured-kubeflow.png

misconfigured-kubeflow.png

Kubernetes threat matrix for the atacks on Kubeflow instances

Image: Microsoft

Weizman said that since April, a cryptomining gang has been scanning for these dashboards, accessing the internet-exposed admin panels, and deploying new server images to Kubeflow clusters, with these images focused on running XMRig, a Monero cryptocurrency mining application.

How to detect hacked Kubeflows

In case server administrators may want to investigate their clusters for any hacked Kubeflow instances, Weizman provided the following steps.

  • Verify that the malicious container is not deployed in the cluster. The following command can help you to check it:

kubectl get pods –all-namespaces -o jsonpath=”{.items[*].spec.containers[*].image}”  | grep -i ddsfdfsaadfs 

  • In case Kubeflow is deployed in the cluster, make sure that its dashboard isn’t exposed to the internet: check the type of the Istio ingress service by the following command and make sure that it is not a load balancer with a public IP:

kubectl get service istio-ingressgateway -n istio-system

Microsoft discovers cryptomining gang hijacking ML-focused Kubernetes clusters 1
blank
About the author

E-Crypto News was developed to assist all cryptocurrency investors in developing profitable cryptocurrency portfolios through the provision of timely and much-needed information. Investments in cryptocurrency require a level of detail, sensitivity, and accuracy that isn’t required in any other market and as such, we’ve developed our databases to help fill in information gaps.

Related Posts

blank

E-Crypto News Executive Interviews


blank

bitcoin
Bitcoin (BTC) $ 38,196.00
ethereum
Ethereum (ETH) $ 2,636.97
tether
Tether (USDT) $ 1.00
binance-coin
Binance Coin (BNB) $ 328.04
cardano
Cardano (ADA) $ 1.36
xrp
XRP (XRP) $ 0.714104
usd-coin
USD Coin (USDC) $ 1.00
dogecoin
Dogecoin (DOGE) $ 0.197206
polkadot
Polkadot (DOT) $ 18.47
binance-usd
Binance USD (BUSD) $ 1.00
USD
EUR
GBP
bitcoinBitcoin (BTC)
$ 38,196.00
ethereumEthereum (ETH)
$ 2,636.97
tetherTether (USDT)
$ 1.00
bitcoin-cashBitcoin Cash (BCH)
$ 530.98
litecoinLitecoin (LTC)
$ 138.58
bitcoinBitcoin (BTC)
32.127,23
ethereumEthereum (ETH)
2.218,00
tetherTether (USDT)
0,841115
bitcoin-cashBitcoin Cash (BCH)
446,62
litecoinLitecoin (LTC)
116,56
bitcoinBitcoin (BTC)
27,416.52
ethereumEthereum (ETH)
1,892.78
tetherTether (USDT)
0.717785
bitcoin-cashBitcoin Cash (BCH)
381.13
litecoinLitecoin (LTC)
99.47

Automated trading with HaasBot Crypto Trading Bots

Crypto Scams

blank
The World’s Most Infamous Crypto Hacks and Scams
July 31, 2021
Cryptocurrency Exchanges
Cryptocurrency Exchanges and the Plague of Scams and Bans
June 29, 2021
blank
What Role Do Cryptocurrencies Play In The Era Of Ransomware Attacks?
June 9, 2021
Crypto Scams On The Rise As Market Enters Bull Cycle
Crypto Scams On The Rise As Market Enters Bull Cycle
December 22, 2020
Harpreet Singh Sahni perpetrated the Plus Gold Union Coin (PGUC) scam
Sydney Concert Promoter Harpreet Sahni Involved In $50M Crypto PGUC Scam
November 2, 2020

Blockchain/Cryptocurrency Questions and Answers

Short-Sell Cryptocurrency
How to Short-Sell Cryptocurrency: A Brief Overview
July 17, 2021
Klaytn
What Is Klaytn (KLAY) And How Does It Work?
July 16, 2021
Cryptocurrencies
Our Crypto Roundup Interview Asks- Do Cryptocurrencies Have a Future?
July 15, 2021
Solana
What Is Solana (SOL) And How Does It Work?
June 26, 2021
blank
What Is Plethori Platform And How Does It Work?
June 12, 2021


CryptoCurrencyUSDChange 1hChange 24hChange 7d
Bitcoin38,067 0.04 % 0.75 % 4.91 %
Ethereum2,629.5 0.54 % 4.44 % 14.34 %
Tether0.9998 0.01 % 0.66 % 0.22 %
Binance Coin327.14 0.35 % 0.82 % 4.28 %
Cardano1.350 0.24 % 0.29 % 5.28 %
XRP0.7139 0.02 % 0.63 % 1.43 %
USD Coin1.000 0.13 % 0.17 % 0.10 %
Dogecoin0.1968 0.02 % 0.47 % 5.57 %
Polkadot18.42 0.02 % 4.82 % 26.68 %
Binance USD0.9980 0.16 % 0.60 % 0.33 %

bitcoin
Bitcoin (BTC) $ 37,561.00
ethereum
Ethereum (ETH) $ 2,567.48
tether
Tether (USDT) $ 0.999798
binance-coin
Binance Coin (BNB) $ 325.03
cardano
Cardano (ADA) $ 1.34
xrp
XRP (XRP) $ 0.706905
usd-coin
USD Coin (USDC) $ 0.998596
dogecoin
Dogecoin (DOGE) $ 0.195103
polkadot
Polkadot (DOT) $ 18.16
binance-usd
Binance USD (BUSD) $ 0.991362