HomeSecurityGhostEngine mining attacks kill EDR security

GhostEngine mining attacks kill EDR security

Malicious crypto mining attacks codenamed “REF4578” were discovered deploying a malicious payload named GhostEngine, which uses vulnerable drivers to disable products and deploy an XMRig miner.

See also: Prison sentence for developer of Tornado Cash cryptomixer

GhostEngine mining attacks

Researchers at Elastic Security Labs and Antiy have highlighted the unusual sophistication of these GhostEngine crypto mining attacks in separate reports, to help defenders detect and stop them.

However, no reports attribute the activity to known threat actors or share details about targets/victims, so the origins and scope of the campaign remain unknown.

While it is unclear how the servers, the attack begins by executing a file named “Tiworker.exe,” which disguises itself as a legitimate Windows.

This executable file is the initial stage of the GhostEngine mining attack, a PowerShell that downloads various modules to perform different behaviors on an infected device.

When Tiworker.exe is executed, it will download a PowerShell script named “get.png” from the attacker’s command and control (C2) server, which acts as the main loader of GhostEngine.

This PowerShell script downloads additional modules and their configurations, disables Windows Defender, enables remote services, and deletes various Windows event logs. Then, get.png verifies that the system has at least 10 MB of free space, which is necessary to promote the infection, and creates scheduled tasks named “OneDriveCloudSync“, “DefaultBrowserUpdate“, and “OneDriveCloudBackup“ for persistence.

See also: Brothers accused of stealing $25 million worth of crypto

GhostEngine mining attacks kill EDR security

The PowerShell script will now download and launch an executable named smartsscreen.exe, which acts as the main GhostEngine payload, to perform the mining attack.

This malware is responsible for terminating and deleting the EDR software and downloading and launching XMRig for cryptocurrency mining.

To terminate the EDR software, GhostEngine loads two vulnerable kernel drivers: aswArPots.sys (Avast driver), which is used to terminate EDR processes, and IObitUnlockers.sys (Iobit driver) to delete the associated executable file.

For persistence, a DLL named 'oci.dll' is loaded by a Windows service named 'msdtc'. When started, this DLL will download a fresh copy of 'get.png' to install the latest version of GhostEngine on the machine.

While Elastic has not seen any impressive figures, it is possible that each victim comes with a unique wallet, so the overall financial gain could be significant.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: FBI: Using unlicensed crypto services leads to financial losses

To protect yourself from crypto mining attacks like GhostEngine, it is important to install and regularly update a reliable antivirus and anti-malware software. In addition, it is important to keep your operating system and all programs up to date, with the latest versions and security patches. Avoid visiting suspicious or untrustworthy websites and downloading files from untrusted sources. These websites and files may contain malware that can install itself on computer and start mining cryptocurrency. Regularly check your computer's resource usage, such as CPU and GPU. If you notice unusually high usage for no apparent reason, this may be a sign of malicious cryptocurrency mining. Use system monitoring tools to detect and stop such activities.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS