HomeSecurityKingminer: Patches vulnerable servers to avoid competitors

Kingminer: Patches vulnerable servers to avoid competitors

Operators of the cryptojacking Kingminer botnet are trying to keep their business competitive by applying hotfixes from Microsoft to vulnerable infected computers to lock out other actors who might claim a piece of their pie.

Kingminer

Kingminer has been around for about two years and continues to brute-force SQL servers to install the XMRig cryptocurrency miner for Monero.

In their latest campaigns, botnet operators have started using the EternalBlue exploit and closed the door to remote access to their compromised systems, a new report from researchers at cybersecurity firm Sophos shows.

From brute force to complete control

The attacks start with Kingminer brute-force that publicly exposes SQL servers until they guess the correct password for the “SA” or system administrator account.

Additional scripts are downloaded after access to the server is gained to allow full control of the system. They use the Microsoft SQL stored procedure "xp_cmdshell" which allows the execution of an SQL statement to launch a Windows command shell.

Since the commands are executed within the MSSQL Windows service, they inherit the same privileges, which are above a standard user. In the end, the attackers have full access to the server via PowerShell commands that give them a remote web shell and install the miners.

EternalBlue and BlueKeep

In recent Kingminer campaigns observed by Sophos, operators used an EternalBlue spreader, although delivery of the script did not result in a successful exploit.

Since it was leaked by the Shadow Brokers hacker group in April 2017, EternalBlue has been frequently used in attacks. The US government ranks it among the top 10 flaws exploited in recent years.

Sophos says that the EternalBlue script used by Kingminer is almost identical to that used by Powerghost/Wannaminer, another crypto botnet.

One component of the malware is a VBScript that checks whether the infected host is running a version of Windows that is vulnerable to the execution flaw (CVE-2019-0708) in Microsoft's RDP protocol: Windows XP, Windows Vista, and Windows 7 to Windows Server 2003 and Windows Server 2008.

In the absence of a hotfix for BlueKeep, Kingminer disables the Remote Desktop Protocol, likely to disable systems from other crypto botnets.

Botnets with BlueKeep scanners are not new. It appears that Kingminer took a page from the Watchbog cryptominer, whose operators added the component in July of last year.

Sophos Kingminer compiles miners into DLLs that are loaded from a benign executable signed with a legitimate certificate.

The Sophos report delves deep into the technical details behind the Kingminer cryptocurrency mining. The researchers’ assessment is that this is a medium-sized criminal enterprise, creative enough to build custom solutions starting from open source projects.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS