A crypto-mining malware that primarily targets Linux- based systems has become even more dangerous thanks to the integration of an open-source remote access trojan, called Chaos RAT . With the malware's advanced capabilities, hackers can take control of remote operating systems.

Security researchers at Trend Micro discovered threat last month. Like previous, similar versions of the miner that also targeted Linux systems, the updated version “kills” competing malware and resources that could hinder the malware’s crypto-mining process.
See also: Fortinet: Fix FortiOS SSL-VPN vulnerability
The newer malware then creates persistence “by modifying the /etc/crontab file, a UNIX task scheduler that, in this case, is downloaded every 10 minutes from Pastebin,” Trend Micro researchers David Fiser and Alfredo Oliveira wrote.
It then downloads an XMRig miner, a configuration file, another payload that removes competing malware, and the Chaos RAT (remote access tool), which is written in Go and has many capabilities, such as rebooting or shutting down the victim.
Additionally, the tool can infiltrate the infected system (reverse shell), take screenshots from the victim's device, collect information about the operating system, and download, upload, or delete files.
See also: Play ransomware: Claimed responsibility for the attack in Antwerp
"An interesting feature of the malware is that the address and access token are passed as compilation flags and are hardcoded into the RAT client," the researchers wrote.

Also, according to the Trend Micro report, the main server used to download payloads appears to be located in Russia, while the Chaos RAT is connected to another command-and-control server believed to be located in Hong Kong.
Researchers also say the Russian server has also been used for cloud bulletproof hosting – services that criminals can use to launch and hide their attacks and other illegal activities. According to Trend Micro, other cybercriminals have used the same hosting service for attacks on cloud infrastructure, containers and Linux servers.
See also: New Python backdoor detected targeting VMware ESXi servers
The researchers argue that the integration of a RAT, in this case Chaos, into crypto-mining malware is not without significance. “On the surface, the integration of a RAT into the infection routine of a crypto-mining malware may seem relatively minor. However, given the tool’s functionality and the fact that this development shows that cloud-based threat actors are continuing to evolve their campaigns, it is important for both organizations and individuals to remain vigilant when it comes to security.”
Crypto-mining malware is increasingly being used by cybercriminals. Organizations need to be aware of this threatso they can take steps to prevent infection. By ensuring their software is always up-to-date and installing antivirus solutions, organizations will be able to better protect themselves from these types of attacks.
Source: www.theregister.com
