A financially motivated threat actor is actively scouring the internet for unprotectedΒ Apache NiFi instancesΒ to covertly install a cryptocurrency miner and facilitate lateral movement.
The findings come from the SANS Internet Storm Center (ISC), which detected a spike in HTTP requests for β/nifiβ on May 19, 2023.
βPersistence is achieved via timed processors or entries to cron,βΒ saidΒ Dr.