Google Alerts Users About Malicious Actors Using Cloud for Cryptocurrency Mining
Google has warned users about the use of its Google Cloud platform by malicious actors to mine cryptocurrencies. In its latest Cloud Threat Intelligence report titled “Threat Horizons,” which provides users with security insights, the company informed that 86% of the compromised instances on Google Cloud platforms were being used to mine cryptocurrencies. Most of the accounts compromised were secured with weak passwords or with no password at all. Google Cloud Used to Mine Cryptocurrencies
Software giant Google is alerting users about malicious actors using compromised Google Cloud accounts for mining cryptocurrency. Google Cloud accounts have access to processing power that can be easily redirected to perform malicious tasks. According to the first “Threat Horizons” report, issued by Google to raise awareness about the security weaknesses in its platform, 86% of the compromised accounts are used for this purpose.
The report states that cryptocurrency mining in the cloud causes high usage of CPU and/or GPU power. It also makes reference to the mining of alternative cryptocurrencies like Chia, which use storage space as a mining resource. Causes and Mitigation
The first cause of the compromise of the examined Google Cloud instances was poor security due to different issues. One of these issues was a weak or inexistent password to access the platform, or a lack of API validation in the instance. With no basic security measures applied, a malicious actor can easily take hold of these platforms. Other cloud platforms are also facing similar problems.
Most of the studied instances downloaded the cryptocurrency mining software in less than 22 seconds after being compromised. This shows that there are systematic attacks of these unsecured instances, with the sole intention being to use them for this purpose. Also, the malicious actors seem to be tracking these unsecured Google Instances actively, given that 40% of the unsecured instances were compromised within eight hours of being deployed. Google stated:
This suggests that the public IP address space is routinely scanned for vulnerable Cloud instances. It will not be a matter of if a vulnerable Cloud instance is detected, but rather when.
To mitigate these risks, the report recommends users follow basic best security practices and implement container analysis and web scanning, tools that will probe the system for security weaknesses using different techniques like crawling. Tags in this story cryptocurrency mining, Google Cloud, Password, unsecured
What do you think about the use of Google Instances to mine cryptocurrency by malicious actors? Tell us in the comments section below. Microstrategy Buys 7,002 More Bitcoins, Growing Crypto Stash to 121,044 BTC NEWS | 56 seconds ago Study Finds Most Popular Cryptocurrencies With Russian Social Media Users NEWS | 12 hours ago
Image Credits: Shutterstock, Pixabay, Wiki Commons Previous articlePlan B Says Bitcoin Price Still ‘on Track Towards $100K’ Despite Missing November’s Price Prediction Next articleSecurity Focused DeFi Project EverRise Upgrades Protocol and Launches on 3 Blockchains Disclaimer: This article is for informational purposes only. It is not a direct offer or solicitation of an offer to buy or sell, or a recommendation or endorsement of any products, services, or companies. Bitcoin.com does not provide investment, tax, legal, or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article. Read disclaimerShow comments More Popular NewsIn Case You Missed ItPaytm Founder: Crypto Is Here to Stay and Will Become Mainstream in 5 Years
The founder of Paytm, a major digital payment company in India, is "very positive about crypto." Noting that cryptocurrency is here to stay, he expects it to become a mainstream technology in a few years. Paytm Founder Is "Very Positive ... read more.‘Financial Inclusion’ — A Buzzword for Central Banks Who Secretly Despise Economic Freedom More Regulations Proposed to ‘Streamline’ Mining Sector in Kazakhstan Retail Giant Newegg Confirms Shiba Inu "Coming Soon" as AMC Theatres Gets Ready to Accept SHIB Payments "We’ve All Decided Centralized Banking Is Rigged" — South Park Episode Features a Bitcoin-Only Future