In a blog post published on Wednesday, Microsoft said its Windows Defender antivirus software helped prevent a massive Cryptojacking malware attack from spreading across the world.
Just before noon on March 6, they blocked about 80,000 such instances of “multiple sophisticated trojans that exhibited advanced cross-process infection techniques, persistence mechanisms, and evasion methods.”.
The trojans were new variants of Dofoil (aka Smoke Loader) and carried a coin mining payload. Within the next twelve-hour period, more than 400,000 infections from their systems were recorded. The attack mainly affected computers in Russia (73%), Turkey (18%), and Ukraine (4%).
Microsoft said that the advanced machine learning models powering the cloud protection service activated the blocking of malware within milliseconds after it was detected by Windows Defender.
“Users affected by these infection attempts would have seen blocks under machine learning names like Fuery, Fuerboos, Cloxer, or Azden. Later blocks appear under the familiar names, Dofoil or Coinminer.”
With the rise in value and popularity of cryptocurrencies like Bitcoin, attackers are more motivated than ever to incorporate mining mechanisms into their attacks. In fact, crypto miners have positioned themselves as an alternative to ransomware.
In total, the malware spread is targeting approximately 500,000 computers in various regions. Various Microsoft operating systems, such as Windows 7, Windows 8.1, and Windows 10 with Windows Defender or Microsoft Security Essentials, are now safe from the threat.
