A newly discovered vulnerability in Drupal has been exploited to turn infected systems into Monero mining bots. Worse, the vulnerability could easily be exploited to do far more than simply steal resources and performance.

Researchers from the Trend Micro Smart Home Network and IoT Reputation Service Teams found the exploits of CVE-2018-7602, a remote code execution vulnerability in Drupal 7 and 8. While the vulnerability was patched on April 25, 2018, many users have yet to move to the current version, leaving an unknown number of Drupal-based websites vulnerable.

The downloader uses the HTTP 1.0 POST method to send traffic, which should be a red flag for security teams since most organizations have moved to HTTP 1.1 or later for their traffic. Once active on a system, the loader installs the a version of the open-source Monero miner XMRig (version 2.6.3) that has had rather simple obfuscation functionality added.

“Patching and updating the Drupal core fixes the vulnerability that this threat exploits,” according to Trend Micro. According to Illusive CEO Ofer Israeli, deception technology can provide a vital layer of protection from advanced persistent threats (APTs) by presenting attackers with seemingly genuine servers that both divert them from high-value digital assets and make it easier to pinpoint malicious network activity.

Bill Mann, Chief Product Officer at Centrify, suggests some strategies for securing today’s perimeter-less enterprise environments – including stronger enforcement of well-defined policies for user access, integration of security into DevOps processes, and smarter use of ML for anomaly detection. Read more from darkreading.com…

thumbnail courtesy of darkreading.com