/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Multiple supercomputers in some EU countries were hacked this week with crypto mining malware via compromised SSH credentials; evidence suggests a single actor

Confirmed infections have been reported in the UK, Germany, and Switzerland.  Another suspected infection was reported in Spain.

ZDNet Catalin Cimpanu

Context & Ripple Effects

This is the third wave of a familiar monetization playbook climbing the hardware stack. The earlier rounds hit commodity infrastructure: an infected plugin that seeded crypto miners across 4,200+ government websites including USCourts.gov and NHS services, then 415K+ MikroTik routers worldwide compromised by CoinHive, Omine, and CoinImp. The Adylkuzz episode showed the same logic at scale — the NSA's EternalBlue exploit, later used in WannaCry, had already been deployed in a possibly larger hack purely to install a cryptocurrency miner.

What is new here is the target class and the entry vector: instead of exploiting unpatched software, the attacker used compromised SSH credentials to log into high-performance computing clusters in the UK, Germany, and Switzerland — with evidence pointing to a single actor, and a suspected related infection reported in Spain.

First-order effects

  • The affected national supercomputing centers in the UK, Germany, and Switzerland must revoke credentials, rebuild compromised nodes, and idle workloads while forensics proceed — directly disrupting research compute capacity.
  • A single-actor signature means every EU HPC site sharing similar SSH access patterns is now treating itself as potentially next in the same campaign.

Second-order effects

  • Other European research centers are pushed toward credential-hygiene overhauls — key rotation, MFA on SSH, access auditing — because this intrusion needed no exploit, only stolen login material.
  • The campaign validates crypto mining as a low-friction monetization path for intrusions into critical infrastructure, the same economics that drove the router and website waves, now applied to clusters whose entire value is raw compute.

Third-order effects

  • If credential-based entry into shared research infrastructure becomes routine, HPC security consolidates around centralized identity and monitoring standards rather than per-site defenses — a structural shift for facilities that historically prioritized open academic access.
  • The escalation path from websites to routers to national supercomputers suggests cryptojacking is becoming a persistent background tax on any under-defended compute layer, reinforcing arguments that states treat domestic compute as strategic infrastructure worth hardening.

The trend: Cryptojacking is migrating from consumer devices and websites up into national research infrastructure, with stolen credentials displacing software exploits as the preferred way in.

Discussion

  • @paulsparrows Paolo Passeri on x
    Multiple supercomputers across Europe have been infected with cryptocurrency mining malware and shut down to investigate the intrusions https://www.zdnet.com/...
  • @littllemel Mel Q on x
    Multiple supercomputers across Europe have been infected this week with cryptocurrency mining malware and have been shut down to investigate the intrusions. Security incidents have been found in the UK, Germany, Switzerland, and possibly Spain. https://www.zdnet.com/...
  • @teriradichel @teriradichel on x
    Supercomputers hacked across Europe to mine cryptocurrency [TR: No published cause but based on past incidents suspect stolen SSH credentials and possible CVE. May affect COVID19 research. MFA, network security + patch] https://www.zdnet.com/...