Hacker News new | ask | show | jobs
by alexginzburg 3490 days ago
we are in the same situation. Early morning today found one host with a high cpu usage. Turned out it was running `./yam` process as a `redis` user. I shut the host down for now. Before shutting it down I did a strace and saw json stream clearly stating that it is a monero app. Looks like the cpu spiked about 12 hours ago. We do have redis on a host but it should be behind the iptables rules. Other hosts look ok.
1 comments

We were able to get in touch with the hacker and he told us he was just mining and not stealing stuff. We're still cleaning the whole system; might even pay him/her a bounty for this though.