HomeSecurityExploiting the BlueKeep vulnerability for cryptomining on Windows systems

Exploiting the BlueKeep vulnerability for cryptomining on Windows systems

The BlueKeep RDP vulnerability in Windows Remote Desktop Services is currently being used by hackers for cryptomining purposes. Attackers exploit vulnerable systems to steal cryptocurrencies.BlueKeep

The attack attempts were observed via honeypots. The security researcher who discovered the attempts is Kevin Beaumont. The researcher noticed that many honeypots in his EternalPot RDP honeypot network began to “crash” and restart. The honeypots had been active for about half a year. Saturday was the first time the malfunction was observed. However, Beaumont noticed that the machines in Australia did not “crash”.

MalwareTech (web name) researcher looked into the issues Beaumont mentioned and concluded that the crash was caused by the BlueKeep vulnerability. MalwareTech said that the attackers used the BlueKeep vulnerability to install a Monero Miner.

MalwareTech's initial analysis showed that an initial payload executes a coded PowerShell command, which downloads a second coded PowerShell script. The final payload is a cryptominer (most likely for Monero).

According to the researcher, the malware is not a worm, but rather exploits the BlueKeep vulnerability en masse . This led the researcher to conclude that the attackers are likely using a BlueKeep scanner , which helps them identify vulnerable systems in order to install the cryptominer.

Exploiting the BlueKeep vulnerability for cryptomining on Windows systems

The researcher also said that the server used to exploit the vulnerability takes the target's IP addresses from a predefined list.

A combination of a cryptominer and a BlueKeep scanner was also reported in July. The malware , which combined these two features, was called Watchbog and primarily targeted Linux servers.

The company Intezer had studied the malware at the time and found that the integration of the scanner "suggests that WatchBog is preparing a list of vulnerable systems that hackers will target in the future or sell to others.".

However, according to MalwareTech, the current attacks are not related to the Watchbog malware.

BlueKeep: A brief history of the vulnerability

The BlueKeep vulnerability (CVE-2019-0708) first surfaced several months ago. Security rated it critical, as it allows malicious software to spread to vulnerable systems without user intervention. Many governments and security companies began warning about the vulnerability's criticality, and Microsoft released a patch on May 14.

Typically, exploiting this RDP vulnerability results in a crash of the target system. The researchers, who created a working exploit, tried to keep the details secret so that hackers could not immediately create their own version and exploit unpatched systems.

Which versions of Windows are affected?

Fortunately, the BlueKeep vulnerability does not affect all versions of Windows. According to Microsoft, hackers can compromise Windows 7, Windows Server 2008 R2, and Windows Server 2008 and install a cryptominer.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS