Torrent: Cybersecurity researchers from two companies (ESET and Malwarebytes) have presented details about a new malware that targets Windows and macOS with Linux-based cryptocurrency mining malware.
It may sound strange, but it's true.
It is called “LoudMiner” and “Bird Miner” and exploits command-line based virtualization software on infected systems to boot a Tiny Core Linux OS that already contains hacker-activated cryptocurrency mining software.

Attackers have been distributing this malware on the Internet via Torrent since August 2018, which contains pirated and cracked copies of VST (Virtual Studio Technology) software.
VST applications contain sounds, effects, synthesizers, and other advanced editing features that allow professionals to create music.
Researchers have found various malicious versions of 137 VST-related applications, of which 42 are for Windows and 95 for macOS, including Propellerhead Reason, Ableton Live, Sylenth1, Nexus, Reaktor 6, and AutoTune.

For macOS systems , the software runs multiple shell scripts and uses the open-source Quick Emulator (QEMU) utility to launch the virtual Linux operating system. For Windows, it relies on VirtualBox.
Once installed and activated, the malware installs additional files and then starts the virtual machines.
The Linux OS images have already been pre-configured by the attackers to automatically launch cryptocurrency mining software without the user having to log in. It then connects to the hacker. command-and-control servers 's

The malware can run two images simultaneously. Each requires 128 MB of RAM and one CPU core.
The attack is another good reason why you should never trust unofficial and pirated software available on the Internet such as the popular, to all of us, Torrent.
