[ad_1]
It didn’t take long for hackers to weaponize a critical Java vulnerability for profit. Using the Log4J exploit, an unidentified actor managed to take control of the AMD-based HP 9000 EPYC servers, turning powerful hardware into cryptocurrency miners. The exploit caused the hash rate of the processor-based Raptoreum (RTM) cryptocurrency (RTM) to double from 200 MH / s to 400 MH / s before most of the exploited machines were taken offline.
Log4J is a recently discovered Java vulnerability as part of the popular Apache suite and deserved the highest possible threat classification (10) according to the “CVSS 3.0” guidelines. This is because the exploit does not require physical access and allows elevation of privilege to trick the system into connecting, downloading and running malware from a server controlled by hackers. Several software vendors fixed the vulnerability, but the HP EPYC 9000 machines did not.
HP’s EPYC server appears to have been targeted for one reason only: to mine Raptoreum (RTM), a processor-based cryptocurrency based on a proof of work (PoW) model that exploits the GhostRider algorithm. Ghostrider combines the x16r and CryptoNight algorithms and plays particularly well with AMD’s dense cache Zen designs. And while AMD’s main Ryzen 9 5900X (12-core) and 5950X (16-core) both have 64MB of L3 cache, the company’s Zen 3-based EPYC Milan processors double that to 128MB, increasing performance levels. performance and daily income. AMD’s next Milan-X EPYC processors are expected to hit the market in Q2 2022. The processors will increase the L3 cache size to 768MB by leveraging 3D V-Cache – one can only imagine the kind of hash rate that the next silicon will be able to unlock.
The developers at Raptoreum first noticed an unusual increase in the hash rate starting on December 9. As the number of machines contributing to Raptoreum has steadily increased, December 9 saw an abnormal jump in the network hash rate from its typical 200 MH / s to a literal doubling, to 400 MH / s – with the increase from a single portfolio. address.
In a statement to EIN News, a leading developer at Raptoreum explained that “During the attack, numerous servers were breached, each producing a significant amount of hash power on very high-end server equipment . Very few organizations in the world have their hands on. Type of material, making it extremely unlikely that the attack was carried out using the individual’s own material. now strong evidence to suggest that the hardware from the Hewlett-Packard 9000 EPYC server was used to mine the Raptoreum coins. “
“We discovered that the miners they were using had all been given HP nicknames and were all abruptly arrested, furthering speculation about a corporate breach followed by a server patch. Log4J mining Raptoreum started on December 9 until it ends mostly on December 17. During this time, hackers were able to collect around 30% of the block’s total reward, or roughly 3.4 million Raptoreum ( RTM), valued at approximately $ 110,000 as of 12/21/2021. Although activity has declined significantly, it is actively mining today on what still appears to be a one-off premium machine that hasn’t been corrected. “
Of the 3.4 million Raptoreum tokens held in the wallet, the hackers managed to move around 1.5 million, cashing them out through the CoinEx exchange. The remaining 1.7 million tokens have been sitting idle – perhaps waiting for positive price action before cashing in the potential profits. Interestingly, Raptoreum’s valuation is unaffected by the portfolio’s sudden action – which would have been in the top 20 portfolios at the 3.4 million RTM mark.
|
Sources 2/ https://www.tomshardware.com/news/hacker-hijacks-hp-epyc-servers-raptoreum-crypto-mining The mention sources can contact us to remove/changing this article |
[ad_2]