Latest in Gear

Image credit: gorodenkoff via Getty Images

Supercomputers across Europe have fallen to cryptomining hacks

They may have been perpetrated by the same attacker.
Jon Fingas, @jonfingas
May 17, 2020
362 Shares
Share
Tweet
Share

Sponsored Links

Photo of Out of Focus IT Technician Turning on Data Server.
gorodenkoff via Getty Images

Cryptomining hacks aren’t new by any stretch, but a string of recent incidents is raising eyebrows. ZDNet reports that culprits infected multiple European supercomputers with Monero mining malware in the past week, including the University of Edinburgh’s ARCHER, five of bwHPC’s computer clusters and most recently a cluster at Munich’s Ludwig-Maximilians University. That’s unusual by itself, but there appears to be a common thread between the hacks.

Cado Security has determined that the attacks were conducted using compromised SSH (secure shell) logins from universities in Canada, China and Poland, using similar malware file names, the same vulnerability and shared technical indicators. That suggests they might be the work of the same bad actor. In the case of ARCHER, the attacks appear to have come from Chinese IP addresses.

If this is a concerted attack, the motivations aren’t completely clear. This could be a pure cash grab that relies on the power of supercomputers to mine digital currency more effectively than regular PCs. However, Cado and others have observed that this comes right as many institutions are repurposing their supercomputers for COVID-19 research. There’s a concern that this may be a roundabout way to steal research or disrupt it. Whatever the reasoning, this isn’t what supercomputer operators wanted at a time when their services are needed the most.

All products recommended by Engadget are selected by our editorial team, independent of our parent company. Some of our stories include affiliate links. If you buy something through one of these links, we may earn an affiliate commission.
Comment
Comments
Share
362 Shares
Share
Tweet
Share

Popular on Engadget

Texas Instruments makes it harder to run programs on its calculators

Texas Instruments makes it harder to run programs on its calculators

View
Samsung Galaxy Note 20 leaks hint at giant screens and S20 Ultra features

Samsung Galaxy Note 20 leaks hint at giant screens and S20 Ultra features

View
Space Station receives the last of NASA's science racks after 19 years

Space Station receives the last of NASA's science racks after 19 years

View
Hacked NES Power Glove controls a modular synth with finger wriggles

Hacked NES Power Glove controls a modular synth with finger wriggles

View
Astronomers spot a strange, first-of-its-kind asteroid near Jupiter

Astronomers spot a strange, first-of-its-kind asteroid near Jupiter

View

From around the web

Page 1Page 1ear iconeye iconFill 23text filevr