HomeSecurityNew worm installs XMRig cryptominers on Windows and Linux servers

New worm installs XMRig cryptominers on Windows and Linux servers

Windows Linux worm

A new Golang-based worm has been discovered that has been spreading and installing XMRig cryptocurrency miners on Windows and Linux servers since at least early December. According to Intezer security researcher Avigayil Mechtinger , this multi-platform worm targets services such as MySQL, Tomcat, and Jenkins that have weak passwords .

Since its discovery, the attackers have advanced the worm's capabilities on the command-and-control (C2) server, which means it is active malware.

The C2 server is used to host the bash or PowerShell dropper script (depending on the targeted platform), a Golang-based binary worm , and the XMRig miner deployed to covertly mine Monero from infected Windows and Linux devices.

"The ELF worm binary and bash dropper script are not detected by VirusTotal yet," Mechtinger said.

Brute-forcing and exploitation of exposed servers

According to the researcher, the worm manages to spread to other computers by scanning and brute-forcing MySql, Tomcat and Jenkins services, using the password spraying and a list of hardcoded credentials.

Earlier versions of the worm attempted to exploit the CVE-2020-14882 Oracle WebLogic RCE vulnerability.

Once it manages to compromise one of the targeted servers, the worm deploys the loader script (ld.sh for Linux and ld.ps1 for Windows), which installs both the XMRig miner and the Golang-based worm binary.

The malware self-destructs if it detects that infected systems are using port 52013. If the port is not in use, the worm will open its own network socket.

New worm installs XMRig cryptominers on Windows and Linux servers

The researcher emphasized that threats targeting Linux systems often go unnoticed, and this is confirmed in this case: “The fact that the worm code is almost identical for both PE and ELF malware, as well as the fact that ELF malware is not detected on VirusTotal, shows that Linux threats are still under the radar of most security and detection.”

How to protect yourself from brute force attacks of this worm?

If you want to protect your Windows and Linux servers from this worm, you should limit connections and use strong and unique passwords on all services exposed to the Internet . In addition, implementing two-factor authentication is essential

Finally, regularly updating your software and all your systems , and ensuring that your servers are not accessible via the Internet, go a long way in preventing such an attack.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS