PGMiner, Innovative Monero-Mining Botnet, Surprises Research

PGMiner, Innovative Monero-Mining Botnet, Surprises Researchers


The malware takes aim at PostgreSQL database servers with never-before-seen techniques.
An innovative Linux-based cryptocurrency mining botnet has been uncovered, which exploits a disputed PostgreSQL remote code-execution (RCE) vulnerability to compromise database servers. The malware is unusual and completely novel in a host of ways, researchers said.
According to researchers at Palo Alto Networks’ Unit 42, the miner (dubbed “PGMiner”) exploits CVE-2019-9193 in PostgreSQL, also known as Postgres, which is a popular open-source relational database management system for production environments. They said this could be the first-ever cryptominer that targets the platform.
“The feature in PostgreSQL under exploitation is ‘copy from program,’ which was introduced in version 9.3 on Sept. 9, 2013,” according to Unit 42 researchers, in a Thursday post. “In 2018, CVE-2019-9193 was linked to this feature, naming it as a vulnerability. However, the PostgreSQL community challenged this assignment, and the CVE has been labeled as ‘disputed.'”

Related Keywords

, Palo Alto Network Unit , Webinar Promo Bug Bounty , Cross Origin Resource Sharing , பாலோ ஆல்டோ வலைப்பின்னல் அலகு , வெபினார் ப்ரோமோ பிழை பவுண்டரி , குறுக்கு ஆரிஜிந் வள பகிர்வு ,

© 2025 Vimarsana