You may remember the NSA leak, called EternalBlue, which was created by a group of hackers in April of last year. The Windows exploit was later used to launch the global cyber disaster known as WannaCry. Another ransomware, Wannamine, also based on EternalBlue, followed a month later.
Now that encryption is at its peak and mining is too, it can leave even the most powerful systems vulnerable. So it wouldn't seem surprising if there was a crypto malware designed to suck the CPU power out of our machines. In fact, we've already seen plenty of it.
Cybersecurity firm Panda Security discovered an encrypted malware last October, which is also powered by EternalBlue.
But another security firm called CrowdStrike said last week that it had seen a spike in WannaMine attacks in recent months. The crypto-mining worm continued to disrupt operations at some companies for days or even weeks while using system resources to mine Monero.
The malware's functionality makes it difficult for companies to take any action against it, as the malware performs an unencrypted operation, meaning it does not download or use any files to infect a system. WannaMine takes the help of built-in Windows components, such as Windows Management Instrumentation (WMI) and PowerShell, to do its job, making it very difficult to detect and stop the malware.
WannaMine uses advanced techniques to move from one system to another on a network. First, it uses the Mimiktaz tool to extract the login credentials of a system. If that fails, it uses the EternalBlue exploit to attack the remote system.
A device can be infected with WannaMine when a user clicks on a malicious link in an email or website. The attacker can also launch a remote access attack on their target.
CrowdStrike says the persistence mechanisms and propagation techniques used by WannaMine are similar to those exploited by national authorities, and the attacks appear to show trends that blur the lines between nation-state and common cybercriminal tactics. But it is different from the WannaCry ransomware, in that it does not lock people out of their computers, as it already generates digital money from mining cryptocurrencies.
WannaMine is not the first of its kind, but its imperfect functionality makes it more sophisticated than other crypto programs like Adyllkuzz, which downloads an application called cpumer. AV software falls short when it comes to dealing with threats that don't write files to disk.
