HomeSecurityWindows and Linux devices are attacked by a new cryptomining worm

Windows and Linux devices are being attacked by a new cryptomining worm

A recently discovered cryptomining worm appears to be increasingly targeting Windows and Linux devices, according to a security researcher.

Windows Linux

See also: North Korean hackers target security researchers again!

Juniper, a research firm, began tracking what it calls the Sysrv botnet in December. One of the botnet's malware components was a worm that spreads from one vulnerable device to another without requiring any action from users. It does this by scanning the Internet for vulnerable devices and, when it finds them, infecting them using a list of exploits that has grown over time.

The malware also includes a cryptominer that uses infected Windows and Linux devices to mine the digital currency Monero. There was a separate binary file for each component.

See also: New worm installs XMRig cryptominers on Windows and Linux servers

By March, Sysrv's developers had redesigned the malware to combine the worm and the cryptominer. They also gave the script that loads the malware the ability to add SSH keys, likely as a way to make it more secure against reboots and to have more advanced capabilities. The worm exploited six vulnerabilities used in enterprises, including Mongo Express, XXL-Job, XML-RPC, Saltstack, ThinkPHP, and Drupal Ajax.

Windows Linux

"Based on the binaries we've seen and the time we've seen them, we've found that malicious actors are constantly updating their exploit arsenal," Juniper researcher Paul Kimayong Thursday.

See also: Hackers breached security cameras of Tesla, Cloudflare and others!

The Juniper Research team discovered that the malware exploits the following vulnerabilities:

  • Mongo Express RCE (CVE-2019-10758)
  • XXL-JOB Unauth RCE
  • XML-RPC (CVE-2017-11610)
  • CVE-2020-16846 (Saltstack RCE)
  • ThinkPHP RCE
  • CVE-2018-7600 (Drupal Ajax RCE)

The threat from this botnet isn't just about straining computing resources and draining power. The malware, which is capable of running a cryptominer, can almost certainly also install ransomware and other malware on Windows and Linux devices. post on Thursday has dozens of indicators that administrators can use to see if their devices are infected.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS