HomeSecurityThis cryptocurrency miner uses unique tactics to hide!

This cryptocurrency miner uses unique tactics to hide!

Researchers have uncovered new obfuscation techniques that they have described as “unique” in an active cryptocurrency mining botnet.

On Thursday, ESET said the discovery was made through an examination of the Stantinko botnet, which has been active since at least 2012.

At launch, Stantinko focused on delivering advertising messages primarily to Russia and Ukraine. The malware spread via pirated software as an infection vector, in which recipients would execute these files only to simultaneously deploy a range of prevention and spyware onto computers.

Revenue would be generated by the operators through malicious browser extensions bundled with the software that performed ad injections and “click fraud,” as well as installing backdoors and performing brute-force attacks on website CMSs.

This cryptocurrency miner uses unique tactics to hide!

In 2019, Stantinko operators added a new cryptocurrency mining unit to generate further illicit revenue and also expanded the group of victims to Russia, Ukraine, Belarus, and Kazakhstan.

The new Monero mining module is interesting, since the “protection techniques encountered during analysis are more advanced than the malware they protect against,” says Vladislav Hrčka.

The ESET malware analyst added that some of the techniques have not yet been “publicly described.”.

Two shielding techniques, the way strings are hidden and a method called flow control scanning, stand out.

The first technique relies on strings, constructed in memory, that only exist in memory when used. According to ESET, all strings embedded in the cryptocurrency module are unrelated to the actual functionality of the miner and “either serve as building blocks for constructing the strings that are actually used or are not used at all.”

"The strings used by the malware are created in memoryto avoid file-based detection and rollback analysis," the researchers note.

Control flow scanning changes the control flow into a form that is difficult to read and the execution of basic blocks is considered “unpredictable”.

A single function is divided into blocks and these blocks are then placed as dispatches in a switch statement within a loop, with each dispatch consisting of a basic block. A control variable determines which block is to be executed.

“The basic blocks are all identified and the control variable always contains the identity of the basic block,” the researchers. “All basic blocks set the value of the control variable to the identity of its successor (a basic block can have multiple possible successors; in this case the immediate “successor” can be selected in a state).”

However, as the code is analyzed at the source code level, common tools to repair this malfunction would not work in the case of the botnet.

The module also confuses some key blocks when connecting dispatches. This whole process constantly causes anomalies in the “flattening loops”, making analysis difficult.

Additionally, threat actors have also implemented pieces of junk code and dead strings, a way to prevent malware as malicious. “Do nothing” code, which executes but has no real functionality, was also found.

“The criminals behind the Stantinko botnet are constantly improving and developing new modules that often contain non-standard and interesting techniques,” says ESET. As the botnet remains active, it is likely that we will see new features or secret techniques in the future.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS