Skip to content

Cybercriminals Hijack Outdated Server for Monero Mining

Hackers are exploiting critical vulnerabilities in older versions of Rejetto’s HTTP File Server (HFS) to install Monero mining malware and other malicious software. This issue, affecting HFS versions up to 2.3m, allows attackers to remotely execute commands without authentication, enabling easy control over the targeted systems.

Cybersecurity firm AhnLab reports that attackers have been deploying various malicious payloads, including XMRig for Monero mining and remote access trojans like XenoRAT and Gh0stRAT. Rejetto has warned users against using versions 2.3m through 2.4, labeling them as dangerous.

Monero is favored by cybercriminals for its high privacy features, which make transactions difficult to trace. XMRig’s efficiency and ability to run on various hardware, coupled with its stealthy operation, make it a popular choice for unauthorized mining.

This exploitation highlights the critical need for regular software updates and vigilance against known vulnerabilities to safeguard system integrity.

Share