AbyssWorker: stealth cryptojacking targeting cloud and containers

Elastic has discovered AbyssWorker, a fileless malware designed to mine cryptocurrency in cloud-based and containerized Linux environments. It leverages shell scripts, LOLBins, and compromised tokens to install itself without leaving traces on disk. Its infrastructure bears similarities to known Chinese cybercriminal groups.

Expert Analysis:
AbyssWorker is not just a “basic” cryptojacker: it targets modern, poorly protected cloud environments using techniques worthy of an APT. Its fileless approach, persistence in ephemeral containers, and use of native system tools make it nearly invisible.

The threat is structural: as long as companies treat their Linux workloads as inherently safe, they will remain blind to these silent attacks. No agent? No alert. No telemetry? No response. And AbyssWorker keeps mining, both literally and strategically.

Read the full article here.

Stay informed with us!

You can subscribe to our monthly cybersecurity newsletter to receive updates about us and the industry

Blog

Check the latest updates on threats, stories, events and analysis.

Cyber Warfare in the US-Israel vs Iran Conflict: What Happened, What It Means, and What To Do

Cyber Warfare in the US-Israel vs Iran Conflict (Roaring Lion & Epic Fury)

Switzerland kicks out Palantir

Switzerland Ends Palantir Contract Over Data Sovereignty Risks – update

Zurich Wants to Buy Beazley | What It Means for Cyber Insurance and Businesses

Zurich Wants to Buy Beazley. Here’s Why That Matters To Cybersecurity.