
Security researchers have discovered a new type of malware that abuses Windows Safe Mode during attacks. The malware, dubbed Crackonosh by Avast researchers , is used for cryptomining and spreads through pirated and cracked software.
See also: ChaChi: The new malware used in attacks against educational institutions
Avast antivirus users began reporting on Reddit the sudden loss of antivirus protection software from the system files. The research team conducted an investigation and found that this is due to infection by a new malicious software.
Crackonosh malware has been in use since at least June 2018. Once a victim executes a file that they believe is a cracked version of legitimate software, the malware is installed as well.
The infection begins with the installation of an installer and a script that modifies the Windows registry to allow the main Crackonosh malware executable to run in Safe Mode. The infected system is configured to run in Safe Mode upon its next boot.
See also: New malware prevents victims from visiting “pirate sites”

“While the Windows system is in Safe Mode, antivirus software is not running,” the researchers say. “This may allow the malicious Serviceinstaller.exe to easily disable and delete Windows Defender.”
Crackonosh scans the system for antivirus programs including Avast, Kaspersky, McAfee's scanner, Norton, and Bitdefender. If it finds any, it attempts to disable or delete them. It then deletes system log files to cover its tracks.
Also, according to researchers, the Crackonosh malware tries to stop Windows Update and replaces Windows Security with a fake icon.
The final step in the infection chain is the deployment of XMRig, a cryptomining malware that leverages system power and resources to mine Monero cryptocurrency (XMR).
Avast researchers say that the Crackonosh malware has given its operators at least 2 million dollars in Monero.
See also: How does the new Siloscape malware compromise Kubernetes clusters?

Approximately 1,000 devices are affected daily and over 222,000 machines have been infected worldwide.
Researchers have identified at least 30 variants of the malicious software. The latest version appears to have been released in November 2020.
“As long as people continue to download cracked software, such attacks will continue and continue to bring profits to the attackers,” Avast says.
Source: ZDNet
