Hackers are exploiting vulnerabilities in the XWiki template system to deploy unauthorized Monero (XMR) mining software on compromised computers. Using scripts like x640, x521, and x522, they install and run the mining program (tcrond) through c3pool.org, while disabling other mining software on the affected machines.
A similar vulnerability has been identified in DELMIA Apriso, allowing remote code execution. To combat cryptojacking, users are advised to block related IP addresses, monitor network connections to c3pool.org, and remove any detected mining files.
Hackers Exploit XWiki and DELMIA Vulnerabilities for Monero Mining
Disclaimer: The content provided on Phemex News is for informational purposes only. We do not guarantee the quality, accuracy, or completeness of the information sourced from third-party articles. The content on this page does not constitute financial or investment advice. We strongly encourage you to conduct you own research and consult with a qualified financial advisor before making any investment decisions.
