
Cryptomining is an easy way for hackers to make money . And according to TechCrunch , the Shellbot Cryptojacking malware has been updated with some new features. The discovery of this updated version was made by Boston-based security firm Threat Slack.
The original Shellbot is capable of brute-forcely stealing SSH remote access credentials on Linux servers protected by weak passwords. The malware then mines Monero (XMR). Threat Stack said the new and updated version can spread across an infected network and disrupt the operations of other miners running on the same machines, allowing the malware to free up more processing power for its own mining process.
According to the research, “the main goal of this campaign appears to be monetary gain through mining and propagation to other systems on the internet.”
Although it is not yet known how the malware is transmitted, researchers have discovered three components as well as the script used to install it.
The malware’s Command and Control server is essentially an Internet Relay Chat (IRC) server, which the attackers used to verify the malware’s status and check the status of an infected server. Using a 272-line script, the malware detects if there are cryptominers on the system and installs its own. Shellbot was making around $300 per day, a number that has steadily increased as the malware spreads.
Shellbot is the latest malware that replaces existing cryptominers instead of simply extracting files.
