Tesla hacked, hackers used the system to mine cryptocurrencies
Tesla hacked, hackers used system to mine cryptocurrency
Elon Musk could send his personal Tesla car into space, change the way humanity generates and store energy, and one day even colonize Mars. Tesla has been hacked, and even today’s Iron Man can’t seem to escape the reach of crypto mining hacks.
Tesla cloud mining
electric car manufacturer Tesla (NASDAQ: TSLA), headquartered in Palo Alto, California ) are among the companies that fell victim to the crypto hijacking, according to data from the cybersecurity firm RedLock.
According to the research of the CSI group, hackers managed to infiltrate Tesla’s Kubernete console, which does not have password protection. In this division; had an Amazon S3 (Simple Storage Service) with sensitive data such as access credentials, telemetry. In addition to data leakage; The hackers were mining cryptocurrencies in one of Tesla’s Kubernetes pods.
The CSI team noted some sophisticated escape methods employed in this attack.. Unlike other crypto mining cases, the hackers did not use a well-known mining pool in this attack.. Instead, they installed the mining pool software and configured the malicious script to connect to an unlisted or semi-public endpoint.. He explained that this makes it harder for standard IP / Domain-based threat intelligence to detect malicious activity.
Don’t panic
According to research; The hackers who hacked Tesla also hid the real IP address of the pool they created while mining behind Cloudflare, a free content delivery network (CDN) service.. Hackers can use an optional new IP address by signing up for free CDN services. This makes IP address-based tracking of cryptocurrency mining activity even more difficult.
The mining software was built to listen on a non-standard port, which makes it difficult to detect activity based on port traffic.. Finally, the CSI team also observed that the CPU usage in Tesla’s Kubernetes dashboard is not very high.. Hackers set it to keep usage low so that mining software would not be detected.
Fortunately, Musk no longer has to worry about his system being used for crypto mining.. The RedLock CSI team immediately reported the incident to Tesla and the issue was resolved quickly.
Bitcoin