TI Mindmap HUB
Threat Intelligence Report

Soco404: Multiplatform Cryptomining Campaign | Wiz Blog

📅 July 24, 2025 📰 www.wiz.io 🔍 1 CVE(s) referenced

A sophisticated, ongoing cryptomining campaign dubbed Soco404 exploits misconfigured and vulnerable cloud services—particularly PostgreSQL—across Linux and Windows environments, using process masquerading, persistence techniques, and compromised legitimate infrastructure to distribute malware and embed itself within a broader crypto-scam operation.

vendor
CVE-2025-24813

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

🔐 Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

📊 Visual Mindmap
🎯 IOC Extraction
⚔️ MITRE ATT&CK TTPs
📦 STIX 2.1 Bundle