New DDoS Attacks Exploit Misconfigured Jupyter Notebooks Using Minecraft Tool

03 Aug 2024

Unveiling the Panamorfi Campaign: A New Wave of DDoS Attacks

Cybersecurity researchers have unveiled a new wave of distributed denial-of-service (DDoS) attacks, specifically targeting misconfigured Jupyter Notebooks. This campaign, dubbed Panamorfi by the cloud security firm Aqua, employs a Java-based tool known as mineping to execute TCP flood DDoS attacks. Originally designed for Minecraft game servers, mineping has found a new purpose in the hands of cybercriminals.

Mechanics of the Attack

The attack strategy involves exploiting Jupyter Notebook instances that are exposed to the internet. By executing wget commands, the attackers can download a ZIP archive from a file-sharing platform called Filebin. Within this ZIP file are two Java archive (JAR) files: conn.jar and mineping.jar. The first file is responsible for establishing connections to a Discord channel, while the second triggers the execution of the mineping package.

Aqua’s researcher, Assaf Morag, explained the objective of this attack: “This attack aims to consume the resources of the target server by sending a large number of TCP connection requests. The results are written to the Discord channel.” This method not only disrupts the targeted servers but also provides real-time feedback to the attackers.

Attribution and Historical Context

The campaign has been linked to a threat actor identified as yawixooo, who maintains a public GitHub repository featuring a Minecraft server properties file. This connection highlights the evolving tactics used by cybercriminals, particularly in leveraging popular platforms for malicious purposes.

This is not the first instance of Jupyter Notebooks being exploited in such a manner. In October 2023, a Tunisian threat group known as Qubitstrike was reported to have breached Jupyter Notebooks, aiming to mine cryptocurrency and infiltrate cloud environments. The recurring targeting of these accessible resources underscores the importance of robust security measures for organizations utilizing Jupyter Notebooks.

As the landscape of cyber threats continues to evolve, vigilance and proactive security practices remain essential for safeguarding digital assets.

Top charts for

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6451118
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1299286
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
499033
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
454646
downloads

News and reviews for

Windows 11 November Update Enhances Start Menu and Taskbar

Windows 11's November update enhances the Start menu and Taskbar while addressing multiple issues. Available as KB5068861 from 2023-11-14.

Read more

Finding Slavek's Purse in Mysteria Ecclesiae DLC

Discover how to locate Slavek's purse in the Mysteria Ecclesiae DLC, enhancing gameplay options.

Read more

Crafting a Plague Mask in Kingdom Come: Deliverance 2

Players can craft a plague mask in Kingdom Come: Deliverance 2 by collecting essential items near Sedletz Monastery.

Read more

Anno 117 Earns Top Rating on Metacritic

Anno 117 outperforms its predecessors in Metacritic scores for 2025 strategy games.

Read more

Windows 11 May Introduce Advanced Haptics for Mice and Trackpads

Microsoft's new 'haptic signals' in Windows 11 could enhance feedback for peripherals, offering a tactile buzz for various actions.

Read more

Arc Raiders Sells Over 4 Million Copies, Sets Player Record

Arc Raiders hits 4 million sales, breaks Steam player record. Nexon's biggest global launch.

Read more

Bethesda Adds Creations Bundle to Fallout 4 Amid Criticism

Bethesda's Creations Bundle for Fallout 4 faces issues: player reports of crashes and missing content.

Read more

Bungie Embraces 'Extraction Shooter' Label Despite Criticism

Bungie sticks with 'Extraction shooter' term for Marathon, despite criticism from former director Chris Sides over its clarity in distinguishing games.

Read more

Steam's Animal Fest 2025 Offers Unique PC Game Deals Until 2023-11-17

Animal Fest 2025 on Steam offers significant discounts on animal-themed PC games, running until 2023-11-17.

Read more

Arcane Trigger Offers Free Steam Demo with Unique Bullet System

Arcane Trigger, a retro wizard shooter by MiniWhale and Anotherindie, releases a free demo on Steam, featuring a unique bullet-building system.

Read more