Security researchers at Palo Alto Networks have discovered a new botnet dubbed “PgMiner,” which targets PostgreSQL databases running on Linux servers to install a cryptocurrency mining program. PostgreSQL, also known as “Postgres,” is one of the most common open-source relational database management systems (RDBMS) for production environments. It ranks fourth among all database management systems (DBMS) as of November 2020.
The botnet performs brute-force attacks against PostgreSQL databases exposed on the internet, while exploiting a controversial PostgreSQL remote code execution (RCE) flaw to compromise the database servers.
Palo Alto Networks researchers reported that the exploited feature in PostgreSQL is the “copy from program” feature, which was released in version 9.3 on September 9, 2013. In 2018, CVE-2019-9193 was linked to this feature, calling it a “vulnerability.” However, the PostgreSQL community disputed this assignment, and the CVE has been marked as “disputed.” Researchers believe that PGMiner is the first cryptocurrency mining botnet delivered through PostgreSQL.”
The attack begins by randomly selecting a network range (e.g. 190.0.0.0, 66.0.0.0) in an attempt to compromise PostgreSQL servers that have port 5432 exposed to the internet.
The PGminer botnet targets Postgress, which has a default user of “postgres,” and performs a brute-force attack that iterates through a built-in list of popular passwords such as “112233” and “1q2w3e4r” to bypass authentication. Once the botnet gains access to the database, it uses the PostgreSQL “COPY from PROGRAM” to download and launch coin mining scripts directly from the underlying server. In addition, the PgMiner botnet is developing a cryptocurrency Monero miner, currently targeting Linux MIPS, ARM, and x64 platforms.

The botnet operators use a command and control (C2) server hosted on the Tor network, which experts say has the same code as the SystemdMiner botnet. Palo Alto Networks researchers also warn that the malware could target all major operating systems. They also observed new techniques, such as embedding the victim's identity in the request, obtaining binary code through multiple approaches, and spoofing a trusted process name.
PostgreSQL is available for all major platforms, including macOS, Windows , and Linux. In theory, hackers could implement another version of PGMiner targeting a new platform, such as Windows, and “deliver” it using PostgreSQL.
It is worth noting that similar attacks have been carried out in 2018 by the StickyDB botnet. Other database technologies that have also been targeted by cryptocurrency mining botnets include MySQL, MSSQL, Redis, and OrientDB.

