s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.pg_mem

📛 Threat Title

Malware family: PG_MEM

Category: PG_MEM First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.pg_mem`. Printable name: PG_MEM.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:advisory.eventussecurity.com

    The PG_MEM malware exploits weak passwords through brute force attacks to infiltrate databases, where it then uses advanced command execution techniques to deploy additional malware . The malware's main objective is to mine cryptocurrency, but it also involves actions to evade detection and maintain persistence on compromised systems.

  • web:cybernoz.com

    Cybersecurity researchers at Aqua Nautilus have uncovered a new malware named PG_MEM that targets PostgreSQL databases. This sophisticated malware employs brute force attacks to gain access, hides within legitimate PostgreSQL processes, and ultimately steals data while mining cryptocurrency. This article delves into the intricate workings of PG_MEM , its attack flow, and its implications for ...

  • web:cybersecuritynews.com

    The first payload, pg_core, is a cryptominer that mines cryptocurrency, while the second payload, pg_mem , is a dropper that deploys the XMRIG cryptominer, memory. Both payloads are designed to evade detection by removing logs, killing competing malware processes, and creating persistence through cron jobs.

  • web:gbhackers.com

    Detection and Remediation Organizations must adopt a defense-in-depth approach to safeguard against PG_MEM and similar threats. This includes implementing strong password policies, regular security audits, and using runtime detection and response tools like Aqua's Runtime Protection.

  • web:hackread.com

    The PG_MEM malware employs a multi-stage attack flow to compromise PostgreSQL databases and deploy cryptocurrency miners. It starts with the attacker initiating a brute force attack on the PostgreSQL database, repeatedly attempting to guess the database credentials. Once this gets done, attackers create a new superuser role with high privileges.

  • web:thehackernews.com

    New PG_MEM malware exploits weak PostgreSQL passwords to mine cryptocurrency, targeting vulnerable databases with brute-force attacks.

  • web:threats.wiz.io

    Researchers have discovered a new PostgreSQL malware called PG_MEM , which uses brute force attacks to access databases, hide its operations, and mine cryptocurrency. The attack involves creating a superuser role, delivering two malware payloads, and evading detection while eliminating competition. Attackers exploit weak passwords and PostgreSQL's command execution capabilities to gain ...

  • web:www.aquasec.com

    Aqua Nautilus researchers have uncovered PG_MEM , a new PostgreSQL malware , that brute forces its way into PostgreSQL databases, delivers payloads to hide its operations, and mines cryptocurrency. In this blog, we explain this attack, the techniques used by the threat actor, and how to detect and protect your environments. About Postgres PostgreSQL, commonly known as Postgres, is a powerful ...

  • web:www.broadcom.com

    PG_MEM is a new malware variant observed recently in the wild. The campaign distributing this malware leverages brute force attacks against vulnerable PostgreSQL database servers. Once the attackers obtain access to the server, an attempt is made to establish persistence by creating a new privileged account.

  • web:www.thaicert.or.th

    129/68 Thursday, April 3, 2025 Cybersecurity researchers at Wiz have uncovered an ongoing campaign targeting externally accessible PostgreSQL servers, exploiting weak or easily guessable credentials to deploy fileless cryptocurrency mining malware . One of the key payloads used in this campaign is a malware strain called PG_MEM , which was first detected by Aqua Security in August

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.