The BlueKeep RDP vulnerability in Windows Remote Desktop Services is currently being used by hackers for cryptomining purposes. Attackers exploit vulnerable systems to steal cryptocurrencies.
The attack attempts were observed via honeypots. The security researcher who discovered the attempts is Kevin Beaumont. The researcher noticed that many honeypots in his EternalPot RDP honeypot network began to “crash” and restart. The honeypots had been active for about half a year. Saturday was the first time the malfunction was observed. However, Beaumont noticed that the machines in Australia did not “crash”.
MalwareTech (web name) researcher looked into the issues Beaumont mentioned and concluded that the crash was caused by the BlueKeep vulnerability. MalwareTech said that the attackers used the BlueKeep vulnerability to install a Monero Miner.
MalwareTech's initial analysis showed that an initial payload executes a coded PowerShell command, which downloads a second coded PowerShell script. The final payload is a cryptominer (most likely for Monero).
According to the researcher, the malware is not a worm, but rather exploits the BlueKeep vulnerability en masse . This led the researcher to conclude that the attackers are likely using a BlueKeep scanner , which helps them identify vulnerable systems in order to install the cryptominer.

The researcher also said that the server used to exploit the vulnerability takes the target's IP addresses from a predefined list.
A combination of a cryptominer and a BlueKeep scanner was also reported in July. The malware , which combined these two features, was called Watchbog and primarily targeted Linux servers.
The company Intezer had studied the malware at the time and found that the integration of the scanner "suggests that WatchBog is preparing a list of vulnerable systems that hackers will target in the future or sell to others.".
However, according to MalwareTech, the current attacks are not related to the Watchbog malware.
BlueKeep: A brief history of the vulnerability
The BlueKeep vulnerability (CVE-2019-0708) first surfaced several months ago. Security rated it critical, as it allows malicious software to spread to vulnerable systems without user intervention. Many governments and security companies began warning about the vulnerability's criticality, and Microsoft released a patch on May 14.
Typically, exploiting this RDP vulnerability results in a crash of the target system. The researchers, who created a working exploit, tried to keep the details secret so that hackers could not immediately create their own version and exploit unpatched systems.
Which versions of Windows are affected?
Fortunately, the BlueKeep vulnerability does not affect all versions of Windows. According to Microsoft, hackers can compromise Windows 7, Windows Server 2008 R2, and Windows Server 2008 and install a cryptominer.
