Recently, a new attack has been taking place via a cryptocurrency-mining botnet . What Hackers is have hidden malware payloads in an image of pop singer Taylor Swift to infect infected computers interesting about this campaign is the way it distributes malware to victims . .
The botnet's name is MyKingz. It is also known as Smominru, DarkCloud or Hexmen.
The story of the MyKingz botnet
The MyKingz botnet first appeared in late 2017. It has been described as the best botnet for cryptomining operations.
Initially, the team behind MyKingz infects Windows, developing various cryptomining applications.
The botnet has one of the most diverse scanning and infection mechanisms on the internet. MyKingz can target everything from MySQL to MS-SQL, from Telnet to SSH, and from RDP to IPC and WMI.
For these reasons, MyKingz managed to grow very quickly and become one of the most effective botnets. In its first few months of existence, it managed to infect more than 525,000 systems Windows and steal $2.3 million worth of Monero
The botnet's attacks were curtailed for a while, leading some to believe it had disappeared. However, reports from Guardicore and Carbon Black showed that MyKingz was still "alive" and infecting a large number of computers (4,700 computers per day).
Taylor Swift
According to a report by Sophos, the latest campaign using the MyKingz botnet was detected this month and targets the United Kingdom.
MyKingz detects vulnerable computers, thanks to its tool , and gains access to them, but it needs a way to deploy malware payloads on infected systems.
Sophos researchers observed that the hackers behind MyKingz use the technique of steganography, which allows them to hide malicious files within legitimate files.
In this particular case, hackers hide a malicious EXE inside a JPEG image of Taylor Swift.
In this way, hackers try to fool the security software that companies to protect their networks. The security will only see that a simple image (JPEG) of Taylor Swift is being downloaded and will not realize that there is also a very dangerous EXE file.

This isn't the first time we've seen a hacking group use steganography or a celebrity's image to distribute malware. Last year, hackers used an image of actress Scarlett Johansson to deploy malware on hacked PostgreSQL databases.
In recent months, hackers have not limited themselves to using images to carry out attacks but have also used other types, such as WAV audio files.
MyKingz is one of the biggest threats to Windows computers in the last two years. Unupdated systems are at risk.
Sophos researchers believe that the group behind the MyKingz botnet earns around $300/day. In total, it has earned its administrators over $3 million.
