HomeSecurityCrackonosh malware: Abuses Windows Safe mode for cryptomining

Crackonosh malware: Abuses Windows Safe mode for cryptomining

Crackonosh malware
Crackonosh malware: Abuses Windows Safe mode for cryptomining

Security researchers have discovered a new type of malware that abuses Windows Safe Mode during attacks. The malware, dubbed Crackonosh by Avast researchers , is used for cryptomining and spreads through pirated and cracked software.

See also: ChaChi: The new malware used in attacks against educational institutions

Avast antivirus users began reporting on Reddit the sudden loss of antivirus protection software from the system files. The research team conducted an investigation and found that this is due to infection by a new malicious software.

Crackonosh malware has been in use since at least June 2018. Once a victim executes a file that they believe is a cracked version of legitimate software, the malware is installed as well.

The infection begins with the installation of an installer and a script that modifies the Windows registry to allow the main Crackonosh malware executable to run in Safe Mode. The infected system is configured to run in Safe Mode upon its next boot.

See also: New malware prevents victims from visiting “pirate sites”

Windows Safe mode

“While the Windows system is in Safe Mode, antivirus software is not running,” the researchers say. “This may allow the malicious Serviceinstaller.exe to easily disable and delete Windows Defender.”

Crackonosh scans the system for antivirus programs including Avast, Kaspersky, McAfee's scanner, Norton, and Bitdefender. If it finds any, it attempts to disable or delete them. It then deletes system log files to cover its tracks.

Also, according to researchers, the Crackonosh malware tries to stop Windows Update and replaces Windows Security with a fake icon.

The final step in the infection chain is the deployment of XMRig, a cryptomining malware that leverages system power and resources to mine Monero cryptocurrency (XMR).

Avast researchers say that the Crackonosh malware has given its operators at least 2 million dollars in Monero.

See also: How does the new Siloscape malware compromise Kubernetes clusters?

Crackonosh cryptomining

Approximately 1,000 devices are affected daily and over 222,000 machines have been infected worldwide.

Researchers have identified at least 30 variants of the malicious software. The latest version appears to have been released in November 2020.

“As long as people continue to download cracked software, such attacks will continue and continue to bring profits to the attackers,” Avast says.

Source: ZDNet

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS