Up to a quarter of all cloud users are at risk of having their computing resources stolen and used to illicitly mine for cryptocurrency, after crims cooked up a campaign that targets publicly accessible DevOps tools. Wiz Threat Research spotted the campaign and attributed it to an attacker it named JINX–0132, which it says exploits misconfigurations and vulnerabilities in multiple applications to deploy mining software. JINX–0132 targets a "wide range" of DevOps tools, but Wiz thinks it prefers HashiCorp’s Nomad and Consul tools, plus Docker API and Gitea. According to threat researchers Gili Tikochinski, Danielle Aminov and Merav Bar, Wiz data indicates that 25 percent of all cloud environments are running at least one of these technologies, and more than 20 percent run HashiCorp Consul. We've asked the Wiz kids how many instances of those applications JINX–0132 hit and will update this story when we hear back from the soon-to-be-Google-owned security shop. "Of those environments using these DevOps tools, five percent expose them directly to the Internet, and among those exposed deployments, 30 percent are misconfigured," the team wrote. Here's a look at the four under–fire tools, and the flaws in each that Wiz says JINX–0132 is looking to abuse. Nomad is a scheduler and orchestrator used to deploy containers and applications across multiple platforms. According to HashiCorp's documentation, Nomad is not secure by default. For example, default settings in the software’s job ...
Illicit crypto-miners pouncing on lazy DevOps configs that leave clouds vulnerable
The Register
·Jessica Lyons
·Published Jun 3, 2025
·Updated
Affected Software
8 affected components
HashiCorp Nomad
HashiCorp Consul
Docker API
Gitea Gitea=1.4.0
Gitea Gitea=1.4.1
HashiCorp Nomad
HashiCorp Consul
Docker API
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses how illicit crypto-miners are exploiting vulnerable DevOps configurations in cloud environments.
2
What security implications are discussed in the article?
The article warns that up to a quarter of cloud users risk having their computing resources stolen for unauthorized cryptocurrency mining.
3
Which software products are mentioned as being targeted by the attackers?
The software products mentioned include HashiCorp Nomad, HashiCorp Consul, Docker API, and specific versions of Gitea.
4
How are attackers exploiting DevOps configurations?
Attackers are taking advantage of publicly accessible DevOps tools that have weak or misconfigured security settings.
5
What can users do to protect their cloud resources from such threats?
Users should secure their DevOps configurations and ensure that sensitive tools are not publicly accessible.