The ongoing Kubernetes cryptomining campaign is now targeting OpenMetadata applications , exploiting critical remote code execution and authentication flaws
See also: New Migo malware targets Redis servers for cryptomining

OpenMetadata is an open source metadata management platform that helps data engineers and scientists catalog and discover data assets within their organization, including databases, tables, files, and services.
The security vulnerabilities used in the attacks , (CVE-2024-28255, CVE-2024-28847, CVE-2024-28253, CVE-2024-28848 and CVE-2024-28254) were patched a month ago, in March, in OpenMetadata 1.2.4 and 1.3.1.
Microsoft ,which first identified the Kubernetes cryptomining attacks, says the five flaws have been actively exploited since early April to compromise OpenMetadata applications that were exposed on the Internet and have not been patched.
"Once they identify a vulnerable version of the application, attackers exploit the reported vulnerabilities to execute code in the container running the vulnerable OpenMetadata," said Microsoft threat researchers Hagai Ran Kestenberg and Yossi Weizman.
“Once the attackers confirm their access and validate connectivity, they proceed to download the payload, a cryptomining-related malware, from a remote server.“
The server hosting the malware payloads also contains additional cryptomining malware for Linux and Windows.
See also: RapperBot botnet: New version with cryptomining capabilities

Kubernetes cryptomining attackers will also leave a note on compromised OpenMetadata systems, asking victims for Monero to help them buy a car or a “suite” in China.
In the next stage, they remove the original payloads from the compromised Kubernetes application and create a reverse shell connection using the Netcat. This gives them remote access to the container, allowing them to take control of the system.
Additionally, to maintain permanent access, attackers use cronjobs to schedule tasks that execute malicious code at predetermined intervals.
Administrators who need to expose OpenMetadata workloads to the Internet are advised to change the default credentials and ensure that their applications are patched to be secure from Kubernetes cryptomining attacks.
To get a list of all OpenMetadata workloads running in your Kubernetes environment, you can use the following command:
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
kubectl get pods –all-namespaces -o=jsonpath='{range .items[]}{.spec.containers[].image}{“\n”}{end}' | grep 'openmetadata'
“ This attack serves as a valuable reminder of why it is vital to remain compliant and run fully patched workloads in containerized environments ,” Kestenberg and Weizman concluded
See also: Vulnerability in Kubernetes allows remote code execution on Windows

How can one protect themselves from cryptomining attacks?
To protect yourself from cryptomining attacks, such as the Kubernetes campaign against OpenMetadata applications, you must first understand their nature. These attacks exploit the processing power of a computer to 'mine' digital currencies without their permission. An effective way to protect yourself is to use antivirus software. Most of these programs provide protection against cryptomining and can detect and remove such threats. Also, keeping your software and operating system up to date is crucial. These updates often include security patches that can protect your computer from new cryptomining threats. Finally, education is a decisive factor. Users should be aware of the techniques used by attackers, such as phishing, and be careful with the emails and messages they receive.
Source: bleepingcomputer
