Tech News

Tech Business News

  • Home
  • Technology
  • Business
  • News
    • Technology News
    • Local Tech News
    • World Tech News
    • General News
    • News Stories
  • Media Releases
    • Tech Media Releases
    • General Media Releases
  • Advertisers
    • Advertiser Content
    • Promoted Content
    • Sponsored Whitepapers
    • Advertising Options
  • Cyber
  • Reports
  • People
  • Science
  • Articles
    • Opinion
    • Digital Marketing
    • Gaming
    • Guest Publishers
  • About
    • Tech Business News
    • News Contributions -Submit
    • Journalist Application
    • Contact Us
Reading: GitLab Exploited To Launch Novel Proxyjacking Attack & Sell Excess Bandwidth For Cash
Share
Font ResizerAa
Tech Business NewsTech Business News
  • Home
  • Technology News
  • Business News
  • News Stories
  • General News
  • World News
  • Media Releases
Search
  • News
    • Technology News
    • Business News
    • Local News
    • News Stories
    • General News
    • World News
    • Global News
  • Media Releases
    • Tech Media Releases
    • General Press
  • Categories
    • Crypto News
    • Cyber
    • Digital Marketing
    • Education
    • Gadgets
    • Technology
    • Guest Publishers
    • IT Security
    • People In Technology
    • Reports
    • Science
    • Software
    • Stock Market
  • Promoted Content
    • Advertisers
    • Promoted
    • Sponsored Whitepapers
  • Contact & About
    • Contact Information
    • About Tech Business News
    • News Contributions & Submissions
Follow US
© 2022 Tech Business News- Australian Technology News. All Rights Reserved.
Tech Business News > Cyber > GitLab Exploited To Launch Novel Proxyjacking Attack & Sell Excess Bandwidth For Cash
Cyber

GitLab Exploited To Launch Novel Proxyjacking Attack & Sell Excess Bandwidth For Cash

Popular web-based platform GitLab falls victim to a sophisticated attack that not only compromised its security but also facilitated an innovative proxy jacking scheme. The new threat operation LABRAT has exploited an already addressed GitLab security vulnerability in a that also involved the utilisation of stealthy malware and command-and-control tools, as well as the TryCloudflare service to conceal malicious activity.

Matthew Giannelis
Last updated: January 11, 2024 3:57 am
Matthew Giannelis
Share
SHARE

GitLab servers have been found to be vulnerable in an ongoing hacking campaign targeting a known flaw allowing proxyjacking and crypojacking attacks. According to a Sysdig report the critical GitLab remote code execution flaw, tracked as CVE-2021-22205, attackers fetch a dropper shell script from a C2 server to establish persistence as system-based SSH credentials.

Contents
Proxyjacking Explored: A New Breed of Cyber AttackThe Intrusion: Breach of GitLab’s SecurityMonetizing Excess Bandwidth

GitLab, a well-known platform used for collaborative software development, experienced a major security incident that revealed the increasing complexity and audacity of modern cyber threats.

The attack, labeled as a “novel proxyjacking attack,” showcased the hackers’ ability to exploit software vulnerabilities for monetary gain in an unconventional manner.

Attackers obfuscated their communication with the C2 servers and deployed a CloudFlare Tunnel, a powerful traffic tunneling solution that allows users to expose local services through the secure Cloudflare network without changing firewall settings or doing port forwarding.

Researchers from GuidePoint Security recently reported an increase in the number of attacks that abused the Cloudflare Tunnel and TryCloudflare.

Researchers also discovered the dropper script’s retrieval of the open-source Global Socket utility to enable cryptojacking and proxyjacking through the ProxyLite and IPRoyal services, as well as a Go-based executable that terminates other mining processes in targeted systems.

A report was released by cybersecurity experts at Sysdig, outlining the activities of a new threat actor they’ve dubbed LABRAT. The group has displayed an extraordinary level of effort to maintain their anonymity, employing a range of techniques such as cross-platform malware, kernel rootkits, and various methods to obscure their actions. Additionally, they’ve exploited legitimate cloud services extensively.

According to the report, “The tactics and tools employed in this campaign surpass the complexity of most incidents encountered by Sysdig TRT. The utilisation of covert and elusive methods in this operation heightens the difficulty of both defense and identification.”

Discovered within three distinct versions of GitLab – 13.8.8, 13.9.6, and 13.10.3 – a patch for the vulnerability has been available since April 2021. This occurrence serves as a reminder of the vital significance of regular updates and the upkeep of both software and hardware.

Upon identifying a vulnerable endpoint and establishing a foothold, the attackers will pursue either proxyjacking or cryptojacking. The former entails leasing unused victim bandwidth to a proxy network, generating revenue in the process.

On the other hand, the latter involves surreptitiously installing cryptocurrency mining software on susceptible devices, without the owner’s awareness or authorisation.

Despite their popularity among cybercriminals, cryptojackers are relatively easy to detect. Due to the resource-intensive nature of crypto mining, the compromised computer becomes sluggish and almost unresponsive while active, as it diverts significant computing power to the mining process.

Proxyjacking Explored: A New Breed of Cyber Attack

Proxyjacking is a type of cyber-attack where hackers compromise a network or system and turn it into a proxy server without the owner’s knowledge.

These proxy servers are then rented or sold on the dark web to various parties, offering them an opportunity to hide their online activities and IP addresses.

The attack on GitLab highlighted a new variant of this technique, where hackers exploited the platform’s infrastructure to create a distributed network of proxy servers.

The Intrusion: Breach of GitLab’s Security

The breach was detected when GitLab users began experiencing slow response times and erratic system behavior. Upon further investigation, GitLab’s security team uncovered unauthorised modifications to the system’s codebase. These modifications allowed the attackers to manipulate the platform’s infrastructure, effectively turning its servers into proxy nodes.

Monetizing Excess Bandwidth

Taking advantage of GitLab’s substantial bandwidth resources, the attackers began renting out the compromised servers’ proxy services to various cybercriminal groups and individuals seeking to anonymize their online activities.

This exploitation allowed the hackers to profit from the excess bandwidth by selling it for cash payments, effectively creating a makeshift botnet that operated as a network of proxy servers.

GitLab went public on the Nasdaq on October 14, 2021 under the ticker symbol “GTLB.”, and its shares haven’t performed too strongly in the intervening months.

The remote-first company currently has a market cap of around $7 billion, substantially down on its $15 billion IPO day valuation and its $19 billion peak a few months later.

The GitLab proxyjacking incident underscores the evolving tactics employed by cybercriminals to exploit vulnerabilities in even the most trusted platforms.

Media Release – Tech News

ByMatthew Giannelis
Follow:
Secondary editor and executive officer at Tech Business News. An IT support engineer for 20 years he's also an advocate for cyber security and anti-spam laws.
Previous Article IoT Software Development Companies - Top 10 Top 10 US IoT Software Development Companies 2025
Next Article Latitude Financial reports $76 million in cyber incident costs Latitude Financial Reports $76 Million In Pre-Tax Costs After March Cyber Security Incident
Leave a Comment

Leave a Reply Cancel reply

You must be logged in to post a comment.

GitLab has been exploited to launch a novel proxyjacking attack

Tech Articles

The Internet’s Best Blogs Didn’t Vanish — They Were Stripped for Parts by SEO Parasites

The Internet’s Best Blogs Didn’t Vanish — They Were Stripped for Parts by SEO Parasites

How some of the internet’s best independent blogs were quietly…

June 3, 2026
Top Big Tech Companies 2026

The Big Tech Companies Actually Winning In 2026 — And Numbers That Prove It

Top tech companies in 2026 included AppLovin, AWS, Microsoft, Meta,…

May 20, 2026

How the World’s Data Centres Are Quietly Burning the Planet

Data centres are burning the planet, with a growing environmental…

March 11, 2026

Recent News

StarLink Cyber Criminal - Attacks
Cyber

Is Starlink The New Tool Of Choice For Global Cyber Criminals?

9 Min Read
Qantas obtains court order to prevent third-party access to stolen data
Cyber

Maurice Blackburn Launches Legal Action for Qantas Data Breach Victims

3 Min Read
Gov flags new rules after Optus hack
Cyber

Federal Government Prepares New Data Breach Notification Rules After Optus Hack.

2 Min Read
Cyber Experts
Cyber

KnowBe4’s Team of Cybersecurity Experts Release Predictions for 2022

6 Min Read
Tech News - Technology Business

Tech Business News

In 2026, technology news is shaping business outcomes faster than ever—driven by AI adoption, rising cyber risk, cloud modernisation, data regulation, and constant platform change.
 
Tech News keeps Australian organisations and industry professionals informed with timely reporting and practical coverage across AI, cybersecurity, cloud, enterprise IT, startups, science, people and business, plus major world and local news impacting the tech sector.
 
Tech Business News publishes news and analysis designed to be clear, relevant, and easy to act on. It supports the industry with technology news reports, whitepaper publishing services, and a range of media, advertising and publishing options 

About

About Us 
Contact Us 
Privacy Policy
Copyright Policy
Terms & Conditions

June, 09, 2026

Contact

Tech Business News
Melbourne, Australia
Werribee 3030
Phone: +61 431401041

Hours : Monday to Friday, 9am 530-pm.

Tech News

© Copyright Tech Business News 

Latest Australian Tech News – 2026

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?