HomeinetSambaCry: massive attack on Linux systems

SambaCry: massive attack on Linux systems

SambaCry Vulnerability: A vulnerability in Samba installations on Linux systems allows attacks for a massive cryptocurrency mining operation.

The malicious users' actions began about five days after the Samba development team announced the creation of patch CVE-2017-7494, which fixes a vulnerability in all versions of Samba released since 2010.SambaCry Vulnerability

Because the vulnerability is exploitable via the SMB protocol and because the issue resembled the vulnerability used by the WannaCry ransomware, some researchers began referring to the bug as SambaCry or EternalRed.

On a technical level, a successful SambaCry exploit allows an attacker to open a “pipe” or conduit into Samba servers, upload malicious code, and execute it. Depending on the attacker’s skill level, one could very easily achieve complete control of the server.

That's exactly what happened. Starting on May 30, hackers began conducting mass scans looking for vulnerable Samba file sharing servers.

After discovering Samba installations, the attackers began loading and running malicious code on their victims' machines.

The attack is carried out with two malicious files: one is a remote shell with full root access, while the second is a modified version of the popular cryptocurrency mining application called cpuminer.

Experts from Kaspersky Labs monitoring the attacks report that the fraudster or fraudsters behind this operation mined Monero cryptocurrency using the Linux systems they managed to hack.

Tracking the attackers was easy because they encoded the Monero wallet address into the EternalMiner source code. So far, researchers report that the hackers have managed to mine 98 Monero, about $5,400 at today's price.

According to security researchers at Rapid7, since the SambaCry issue became known, there were approximately 104,000 computers exposed to the Internet using vulnerable versions of the Samba software as of May 25. The number has decreased as many administrators have updated their systems, but there are still many vulnerable servers that allow file sharing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS