One server, three crypto crimes: wallet scanning, cryptojacking and pool brute-forcing
Not every exposed attacker server is subtle. On 23.252.123.134, a host at WebNX, Inc., an open directory laid out an entire Chinese-language cryptocurrency-theft operation, three separate money-making rackets wired to one control server.
Key findings
- Three rackets, one control server. Wallet-key scanning, cryptojacking and mining-pool brute-forcing all stage payloads from, and report hits to, the same host (ports 8000/18095 for staging, 8899 for callbacks).
- Stolen compute. The wallet scanner runs "inside hijacked YARN containers", Hadoop/YARN clusters are big, exposed and rarely watched, a long-standing cryptojacking target.
- Textbook covert miner. A GPU-aware installer hides in
/tmp/.scXXXX, exposes xmrig-style local APIs and persists via two crontab entries. - Theft layered on theft. Distributed workers brute-force a mining-pool platform's accounts to redirect other miners' payouts.
Architecture
Figure 1. Three independent rackets, one shared control server and callback port.
How we found it
The host surfaced as a malicious open directory, worker scripts, mining binaries and a credential dictionary served straight out of an exposed HTTP root. We recovered and classified the contents automatically. Sensors place it on 2026-09-27.
1. Wallet key-scanning on stolen compute
The first racket is a distributed wallet-key scanning engine. A worker (qhmine_worker.sh, with Chinese comments noting it runs "inside hijacked YARN containers") pulls a native engine binary and a fuse16 filter set from the control server, then sweeps an assigned numeric range looking for funded wallets, bounding itself to eight threads per host and posting any hits back to a collector. The filter is almost certainly a precomputed set of funded addresses: the engine checks generated or harvested keys against it. The compute is not theirs, it runs inside hijacked Hadoop/YARN clusters, big, internet-exposed and rarely watched.
2. A GPU-aware cryptojacking fleet
The second racket is straightforward mining. deploy_node.sh is a textbook covert-miner installer: it hides in a randomly named /tmp/.scXXXX directory, pulls a fleet_lin.tgz bundle, launches a miner that exposes the familiar xmrig-style local APIs (:4068, :4069/2/summary), checks for a GPU with nvidia-smi, and persists through two crontab entries (@reboot and every eight minutes).
3. Mining-pool credential brute-forcing
The third racket targets the accounts of a cryptocurrency mining-pool platform (anonymised). Two workers, a bash/curl version (krworker.sh) and a long-running Python one (worker3.py), split a shared dictionary (mega_dict.txt) across a cluster by index, rotate user-agents and SOCKS proxies, fetch the login CSRF token and grind credentials for a list of target usernames, reporting hits to the control server on port 8899. Compromised pool accounts let the operator redirect other miners' payouts.
Attribution
Every worker carries Chinese-language comments and operational notes, placing a Chinese-speaking operator or crew behind the infrastructure. As always, language is an attribution lead, not a link to a named group. The three rackets share one control server and callback port, so this is one operation with three revenue streams, not three unrelated tools.
MITRE ATT&CK
| Technique | Name | Observed via |
|---|---|---|
| T1496 | Resource Hijacking | xmrig-style miner fleet; wallet-scan on YARN |
| T1110.001 | Brute Force: Password Guessing | krworker.sh / worker3.py vs a mining pool |
| T1053.003 | Scheduled Task/Job: Cron | @reboot + */8 persistence |
| T1564.001 | Hide Artifacts: Hidden Files and Directories | /tmp/.scXXXX miner dir |
| T1090.002 | Proxy: External Proxy | rotating SOCKS proxies in the brute-forcer |
Indicators
Defending against it
- Lock down Hadoop/YARN: never expose the ResourceManager REST API to the internet; it is the most common entry point for this kind of cluster cryptojacking.
- Hunt the persistence: look for
/tmp/.sc*directories, crontab entries running a hidden binary every few minutes, and local miner APIs on 4068/4069. - Protect pool accounts: enforce MFA and rate-limit logins; this crew brute-forces them at scale from distributed workers.
Browse the running list of exposed C2 and malware infrastructure on live finds, or start free and hunt your own.
New attacker-infrastructure writeups and live indicators, straight to your inbox. No spam, unsubscribe anytime.
Hunt it yourself
Classify any IP, browse live attacker infrastructure, or deploy your own sensors. Free, no card.