HomeSecurityHeadCrab malware: Infects 1,200 Redis servers for Monero mining

HeadCrab malware: Infects 1,200 Redis servers for Monero mining

The new HeadCrab malware designed to prey on vulnerable Redis servers online has infected more than a thousand of them since September 2021 to create a botnet that mines Monero cryptocurrency.

HeadCrab malware

Aqua Security researchers Nitzan Yaakov and Asaf Eitani recently discovered HeadCrab, a malware that has successfully infiltrated over 1,200 servers. And what’s worse, these malicious programs continue their search for more vulnerable targets online.

See also: Hackers use IceBreaker malware to compromise gaming companies

By exploiting the lack of authentication on Redis servers, threat actors are able to exploit this weakness, as they were not designed to be accessible over public networks. This leaves them open and vulnerable to a malicious attack that can easily be launched by a botnet.

If administrators fail to ensure they are secure and misconfigure them so that external entities can access them , malicious actors can exploit this vulnerability using unauthorized tools or malware. This could potentially lead to the device being hacked by attackers.

Once they gain access to servers that do not require authentication, the malicious actors execute a “SLAVEOF” command to synchronize a master server under control to deploy the HeadCrab malware to the newly compromised system.

Once deployed and activated, HeadCrab gives malicious actors the power to take ownership of the targeted server and integrate it into the cryptomining botnet.

This malware can not only run in memory to evade anti-malware scans, but has also proven undetectable with samples analyzed by Aqua Security on VirusTotal.

Furthermore, it deletes all files and only communicates with other servers managed by the same owners, in order to remain hidden.

See also: LockBit Green ransomware: New version is based on Conti's source code

Redis servers

While studying the malware, they discovered that the attackers are using mining pools hosted on previously compromised servers to hide their identity and avoid detection.

Additionally, the Monero wallet associated with this botnet shows that the attackers earn an estimated annual income of around $4,500 per employee. This amount is significantly higher than what other similar businesses – typically only around $200/employee.

See also: InTheBox: Over 1,800 malicious phishing forms available

To defend Redis servers, administrators are advised to ensure that only clients within their networks can access them, disable the “slaveof” feature if not in use, and enable protected mode, which configures the instance to respond only to the return address and deny connections from other IP addresses.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS