Over the summer, security noticed an increase in the number of attacks with cryptomining malware.
The main reason for this sudden increase is the revival of the cryptocurrency market. Trading prices have started to recover after the big drop in late 2018.
Most of the cryptomining campaigns that occurred during this time targeted Monero. The cryptocurrency, also known as XMR, tripled in value over the summer, reaching around $115. This increase did not go unnoticed by hackers.
Criminals focused on this and began to carry out more and more cryptomining attacks targeting Monero.
Most attacks were recorded from late May onwards. Security companies reported new incidents continuously. Many times, there were updates about daily attacks.

Cryptomining malware
Cryptomining malware began to pose a threat in the late 2000s, when Bitcoin emerged. Initially, malicious hackers created malware that targeted Bitcoin. However, as mining became more difficult, hackers began to turn to other cryptocurrencies.
Monero has slowly become a favorite target for criminals. However, the campaigns started to become more organized when Monero reached its highest price ($480) in late 2017 and early 2018.
At that time, most hacking groups were creating Monero mining malware and carrying out attacks. It had become the most common form of malware.
The most popular groups-campaigns were: Digmine, Hexmen, Loapi, Zealot, WaterMiner, CodeFork, Bondnet, Adylkuzz, CoinMiner, Linux.BTCMine.26, Zminer, DevilRobber, PyCryptoMiner, RubyMiner and MassMiner.
From mid to late 2018, the price of Monero dropped significantly. This also resulted in a decrease in attacks. They did not stop completely, but they were happening on a smaller scale.
Now with the rise in the value of cryptocurrency, attacks have started to become more frequent again.
Cryptomining……. summer
Here are some of the most popular cryptomining campaigns of the summer.
May 2019: Researchers noticed that two groups, Rocke and Pascha, were trying to steal Monero by infecting Linux and cloud-based applications.
May 2019-Nansh0u Campaign: – A Chinese group infected over 50,000 Windows MS-SQL and phpMyAdmin servers to steal Monero.
May 2019 -RIG exploit kit: Researchers discovered that the kit used a Monero miner as its final payload. The crypto-miner targeted Windows desktop users.
June 2019: A new malware, named BlackSquid. It targets both Windows and Linux servers.
June 2019: A botnet (AESDDoS Botnet) used to carry out DDoS attacks began spreading malware for mining Monero.
June 2019: An anonymous campaign, which affected webservers and used cronjob.
June 2019: Researchers discovered a new malware, called Plurox. Its main target was Windows.
June 2019: Hackers used another software, LoudMiner, which targets both MacOS and Windows.
June 2019: Researchers described a Monero mining campaign in which hackers scanned the internet for Android that exposed their ADB.
July 2019: The WatchBog Cryptocurrency-mining botnet affected over 4,500 Linux machines.
August 2019: The Smominru botnet was used for Monero mining and credential theft.
August 2019: Security researchers discovered a new crypto-miner, known as Norman. It targets Windows systems only.
September 2019: – New Skidmap Linux malware used to install cryptominer on web servers. Targets Debian and RHEL/CentOS systems only.
September 2019: The latest cryptomining campaign, revealed yesterday, comes from the Panda. It uses known exploits published by other groups and affects web servers.
The above campaigns show that hackers were very active during the summer. Some groups preferred to use well-known cryptomining software or evolve others to be used for cryptomining, while others developed new ones.
What was found is that when the price of Monero increased, new software began to appear.
Changes in the value of cryptocurrencies could be an early warning of an increase or decrease in cryptomining attacks.
The good news is that when a particular type of attack occurs frequently, become security companies familiar with it and start providing better protection.
