Hackers turn supercomputers into cryptocurrency mining rigs


Hackers have manage to install cryptocurrency mining malware on multiple supercomputers across Europe that have now had to shut down as they investigate.
Security incidents at facilities housing supercomputers were reported in the UK, Germany and Switzerland while a similar breach was also rumored to have occurred at a high-performance computing center located in Spain.
The University of Edinburgh, which runs the ARCHER supercomputer, suffered the first attack and the organization reported that it had disabled access to the system and reset SSH passwords due to a security exploitation on the ARCHER login nodes. On the same day, the organization responsible for coordinating research projects across supercomputers in the German state of Baden-Württemberg, bwHPC announced that five of its high-performance computing clusters were shut down following similar security incidents.
Later in the week, the Bavarian Academy of Sciences’ Leibniz Computing Center (LRZ) announced that it had disconnected a computing cluster from the internet following a security breach. Officials from the Julich Research Center then announced that they shut down the JURECA, JUDAC and JUWELS supercomputers after an IT security incident. The Technical University in Dresden also announced that it had to shut down its Taurus supercomputer as well.
Targeting supercomputers
While none of the organizations whose supercomputers were affected by these security incidents have published any details on them, the Computer Security Incident Response Team (CSIRT) for the European Grid Infrastructure (EGI) has released malware samples and network compromise indicators for some of the attacks.
After reviewing these malware samples, the UK-based cybersecurity firm Cado Security believes that the attackers like gained access to the supercomputer clusters by using compromised SSH credentials. These credentials appear to have been stolen from university staff from Canada, China and Poland who were given access to the supercomputers to run demanding and complex computing jobs.
Cado Security’s Co-Founder Chris Doman told ZDNet that similar malware file names and network indicators suggest that these security incidents may have been carried out by the same threat actor. Based on his analysis, the attacker leveraged the CVE-2019-15666 vulnerability in the Linux kernel to gain root access and then deployed an application to mine the Monero cyrptocurrency.
Having to take down this many supercomputers at once due to security incidents is unprecedented and unfortunately, many of these systems were being used to research and study Covid-19 at the time.
Via ZDNet
Hackers have manage to install cryptocurrency mining malware on multiple supercomputers across Europe that have now had to shut down as they investigate. Security incidents at facilities housing supercomputers were reported in the UK, Germany and Switzerland while a similar breach was also rumored to have occurred at a high-performance…
Recent Posts
- One of the best AI video generators is now on the iPhone – here’s what you need to know about Pika’s new app
- Apple’s C1 chip could be a big deal for iPhones – here’s why
- Rabbit shows off the AI agent it should have launched with
- Instagram wants you to do more with DMs than just slide into someone else’s
- Nvidia is launching ‘priority access’ to help fans buy RTX 5080 and 5090 FE GPUs
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010