When Ops Turn Rogue: Inside Baidu’s 2018 Crypto‑Mining Scandal
A Baidu operations engineer illegally mined cryptocurrency on more than 150 company servers in 2018, netting over 100,000 RMB, was caught, sentenced to three years in prison and a fine, and the case now serves as a stark reminder of insider threats and the need for strict access controls in IT operations.
In early 2018, Baidu employee An, an operations staff member, exploited his privileged access to upload a compressed file miner.tar.gz containing a script named java_4u3. The script automatically unpacked, created directories, deleted traces, and connected to a proxy to gain control over the target servers.
Using the script, An deployed a custom cryptocurrency‑mining program on more than 155 Baidu servers. The malicious code hijacked the servers’ CPU cycles to mine Bitcoin and Monero, sending the generated hashes to a hash‑site that paid out in Bitcoin, which An later converted to cash via otcbtc.com.
The operation yielded roughly 100,000 RMB in profit. After the mining activity was detected by Baidu’s security monitoring system in June 2018, an investigation identified An as the perpetrator. Baidu spent 27,000 RMB on emergency forensic services to extract logs, analyze samples, and trace the breach.
In July 2018, Baidu filed a lawsuit against An for illegal control of a computer information system. The court sentenced him to three years in prison, confiscated 110,000 RMB of illicit gains (with 11,000 RMB offset as a fine), and ordered the return of seized equipment.
The case highlights the significant risk posed by insiders with privileged access, especially in operations roles that manage critical infrastructure. Experts recommend implementing strict approval, logging, and verification procedures for all production‑system actions, separating duties for backup and restoration, and fostering professional ethics among operations staff.
Signed-in readers can open the original source through BestHub's protected redirect.
This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactand we will review it promptly.
21CTO
21CTO (21CTO.com) offers developers community, training, and services, making it your go‑to learning and service platform.
How this landed with the community
Was this worth your time?
0 Comments
Thoughtful readers leave field notes, pushback, and hard-won operational detail here.
