Author

Topic: Google Cloud accounts can be compromised to install cryptojacking & other malwar (Read 84 times)

legendary
Activity: 1512
Merit: 4795
Leading Crypto Sports Betting & Casino Platform
According to the report by Google Cyber Security Action Team, a report that shows how it is possible for Google cloud accounts to be compromised with malware, among the malware, cryptojacking is the most frequent with 89%. The compromised Cloud accounts was used by the attackers to access people's CPUs or GPUs to mine or take advantage of storage space according to the report.








Quote
Time was of the essence in the compromise of the Google Cloud instances. The shortest amount of time between deploying a vulnerable Cloud instance exposed to the Internet and its compromise was determined to be as little as 30 minutes. In 40% of instances the time to compromise was under eight hours. This suggests that the public IP address space is routinely scanned for vulnerable Cloud instances. It will not be a matter of if a vulnerable Cloud instance is detected, but rather when.

Analysis of the systems used to perform unauthorized cryptocurrency mining, where timeline information was available, revealed that in 58% of situations the cryptocurrency mining software was downloaded to the system within 22 seconds of being compromised as shown in Figure 1. This suggests that the initial attacks and subsequent downloads were scripted events not requiring human intervention. The ability to manually intervene in these situations to prevent exploitation is nearly impossible. The best defense would be to not deploy a vulnerable system or have automated response mechanisms.

For sucurity and safety:
Enssuring email best practice
Use of authentication for account security
The use of Tor should also help by relaying different circutes (I guessed this because IP address are first targeted, not account)

To read the full report:
https://services.google.com/fh/files/misc/gcat_threathorizons_full_nov2021.pdf

Or best to avoid Google Cloud?
Jump to: