Security researchers at Check Point discovered a new malware variant that is spreading on the internet, named RubyMiner. It is primarily found on web servers and its purpose is to perform cryptocurrency mining.
The RubyMiner uses a fingerprinting tool called “p0f” for scanning and identifying Windows and Linux servers that use outdated software. After they discover those specific servers, they try to gain access to them and infect them with the specific malware. The victims are usually the IIS servers of Windows. In a report published last week, Check Point reports that it broke the code used by RubyMiner on Linux systems in order to better understand how it works.
Generally, in recent months there have been increases in attempts to spread malicious software for cryptocurrency mining, which focus on Monero Coin. It has only been two weeks since 2018 began and we have already seen 2 new dangerous malware for servers. The PyCryptoMiner that targets Linux servers and another one that targets Oracle WebLogic servers. Of course, the attacks of RubyMiner are unusual because the intruders use very old exploits, which most security software can detect and delete. Because’of this reason the security researchers at Check Point believe that the attacking users target forgotten computers and servers with old operating system versions that are still on the Internet.
The number of servers infected with RubyMiner amounts to 700 and the attackers' profits are estimated at about $540, based on the wallet addresses that were found.
