Security researchers at Russian antivirus company Dr.Web have discovered a new Linux cryptominer strain detected as Linux.BtcMine.174.
The Linux cryptominer has a multi-component structure, implementing a wide range of features in over 1,000 lines of code.
When the Monero Linux cryptominer is initially executed, it checks if the server from which the Trojan will then download additional components is available.
It then finds a folder on the disk to which it has write permissions so it can copy and use it as a repository for downloading additional modules.
The Linux.BtcMine.174 Linux cryptominer uses one of two privilege escalation exploits, CVE-2016-5195 (aka Dirty COW) and CVE-2013-2094, to gain root privileges on the infected system.
The Linux miner also adds itself as an autorun to files such as /etc/rc.local, /etc/rc.d/…, and /etc/cron.hourly. and then downloads and runs a rootkit.
Once the malware has infected the Linux, it will scan and terminate the processes of several miners and scan /proc/${pid}/exe and /proc/${pid}/cmdline to check for specific lines (e.g. +tcp, etc.). Experts have discovered that the Trojan also terminates the operation of antivirus software, including Avast, AVG, Dr.Web, and ESET.
Linux.BtcMine.174. then downloads and launches its own Monero cryptominer.
The malware also downloads another Trojan, detected as Linux.BackDoor.Gates.9, which implements backdoor features and allows for DDoS attacks. Linux.BtcMine.174, is downloaded and executed with the ability to steal passwords entered by the user for the su command and hide files in the file system, network connections, and running processes.
The Trojan also collects data about all hosts that the user has previously connected to via SSH and attempts to connect to.
Experts believe that the malware is spreading using stolen SSH credentials on infected systems.
Additional technical details are included in the report published by Dr.Web and on GitHub.
