Over 1,500 PostgreSQL servers have been compromised in a fileless cryptocurrency mining campaign. Threat actor JINX-0126 gains unauthorized access through weak credentials and SQL abuse, then deploys miners filelessly to evade detection. The attack uses the COPY ... FROM PROGRAM SQL command to execute arbitrary shell commands and establish persistence on the host.
9 Impressions