• About us
  • Contact Us
  • Privacy & Policy
CryptoCoinNewsHub.com
No Result
View All Result
Thursday, July 9, 2020
  • Home
  • Live Updates
    • Cryptocurrency Prices
    • Live ICO
    • Live Exchange
  • Crypto News
    • Bitcoin
    • Ethereum
    • Ripple
  • Blockchain
  • Tech
  • Business
  • Trading
CryptoCoinNewsHub.com
  • Home
  • Live Updates
    • Cryptocurrency Prices
    • Live ICO
    • Live Exchange
  • Crypto News
    • Bitcoin
    • Ethereum
    • Ripple
  • Blockchain
  • Tech
  • Business
  • Trading
No Result
View All Result
CryptoCoinNewsHub.com
No Result
View All Result
Home Crypto News

New Malware Scours Linux Servers for Monero

July 4, 2019
in Crypto News
3 min read
0
New Malware Scours Linux Servers for Monero
152
SHARES
1.9k
VIEWS
Share on FacebookShare on Twitter

New Malware Scours Linux Servers for Monero, CryptoCoinNewsHub.com

A new type of crypto malware,Golang, has been identified, being set up to fraudulently mine Monero (XMR) cryptocurrency on Linux servers.

Many cybersecurity companies have been releasing reports on the new malware, which is called Golang, that is capable of infecting Linux servers by using different infection tactics.

Josh Grunzweig, Palo Alto Networks Unit 42 cybersecurity researcher, believes that new malware has been developed using this language in the past months, with most of them focusing on attacking the Microsoft Windows operating system.

Grunzweig gathered more than 10,000 unique samples of Go-compiled malware and concluded that the most common malware families were Veil, GoBot2, and Hercules. Pentesting, Remote Access Trojans (RATs), and backdoors were the most used developments.

Trend Micro researchers Augusto Remillano II and Mark Vicente said the propagator was being used to insert a cryptocurrency miner payload.

Golang was first detected in May and the malware specifically targets Linux servers. The code looks for vulnerabilities in the system as well as entry points through which they can spread to networks.

According to F5 researchers, Golang has 7 propagation methods; “4 exploits targeting web applications (2 exploits targeting ThinkPHP, 1 targeting Drupal, and 1 targeting Confluence), enumeration of SSH credentials enumeration, enumeration of Redis database credentials, and attempts to connect other machines using found SSH keys.”

The malware first sends a GET request to http://ident.me, a service which returns the public IP address of a server. The IP list is then used to create a list of IP addresses in the same Class B, after which it scans 80, 20, 8090, and 6397 ports. Then a malicious request is sent to the found ports to download a payload on Pastebin.

With Confluence, the malware uses the CVE-2019-3396 vulnerability, which in the past has been exploited by cryptocurrency mining malware.

In a Redis attack, if no open ports are detected, the malware goes on to test simple passwords — such as admin, root, redis, and test – in order to establish a connection to a weak server.

RELATED  Canadian Company Launches CAD Stablecoin

Golang then removes the existing database through the FLUSHALL Redis command and then develops a scheduled task to replace it with the payload download.

The propagator also deactivates all security tools and software, deletes clear histories and logs, and looks for other cryptocurrency mining operations in operation to terminate them – keeping all CPU power to their mining activities. Also, all processes that consume over 30 percent of the available memory resources will be terminated.

Golang installs itself as a cron job and service in the system called mysqlc. The download script is then verified and re-executed every 15 minutes.

The malware blocks outgoing traffic on ports 3333, 5555, 7777, and 9999, as these ports are used for other crypto mining activities.

Golang uses a popular XMRig 2.13.1Monero mining script. F5 traced the malware to several public mining pools where under $2,000 has been earned so far. “However, this information is based only on the wallets our specific miners were using. It could be that the attacker has several wallets used by different parts of his botnet.”

It was found that the potential author of the malware goes by the username of “Nidaye222.” “Ni da ye” has a double meaning in Chinese, either uncle or something rude, depending on the context.

F5 researches traced a “GitHub profile with the same username that was created a couple of days prior to this writing. That user recently forked an open source vulnerability detection system. It is possible that this is a research hub for the malicious actor where he or she could be experimenting with additional exploits in order to expand the current campaign.”

Although Golang is not one of the most sophisticated malware in the crypto scene, its number of propagation methods, although simple, show that the creator is more into quantity than quality. Alas, this will probably not be the last time we hear about Golang.

Featured Image: The Merkle Hash

Credit: Source link

  • Trending
  • Comments
  • Latest
Circle Looks to Raise $100M for Its Equity Platform SeedInvest

Circle Looks to Raise $100M for Its Equity Platform SeedInvest

August 23, 2019
Bitcoin is Absolutely Clobbering Your Favorite Altcoin This Season

Bitcoin is Absolutely Clobbering Your Favorite Altcoin This Season

July 5, 2019
Iran’s Government Officially Legitimizes Cryptocurrency Mining

Iran’s Government Officially Legitimizes Cryptocurrency Mining

July 29, 2019
Google’s ‘Quantum Supremacy’ Has No Impact on Bitcoin

Google’s ‘Quantum Supremacy’ Has No Impact on Bitcoin

October 11, 2019

Confiscated Bitcoins by Tax Agents Remain in a Criminal’s Wallet

February 7, 2020

XRP Beats Ethereum and Bitcoin as the Best Performing Crypto

February 1, 2020

Robin Hood- Problems in more than just Sherwood Forest

January 28, 2020

One Wallet Has 27% of Ether in Old MakerDAO Network

January 26, 2020
CryptoCoinNewsHub.com

CryptoCoinNewsHub.com is an online news portal which aims to provide latest trendy crypto news around the world with real time updates.
Email us hello@cryptocoinnewshub.com

Topics to Cover

  • Bitcoin
  • Blockchain
  • Business
  • Crypto News
  • Ethereum
  • Ripple
  • Tech
  • Trading

Whats New Here!

  • Confiscated Bitcoins by Tax Agents Remain in a Criminal’s Wallet
  • XRP Beats Ethereum and Bitcoin as the Best Performing Crypto
  • Robin Hood- Problems in more than just Sherwood Forest

Subscribe to get more

Simply subscribe to our newsletters and we will be in touch. Don't worry, we won't spam you

© 2019 CryptoCoinNewsHub.com - All rights reserved

No Result
View All Result
  • Home
  • Live Updates
    • Cryptocurrency Prices
    • Live ICO
    • Live Exchange
  • Crypto News
    • Bitcoin
    • Ethereum
    • Ripple
  • Blockchain
  • Tech
  • Business
  • Trading

© 2019 CryptoCoinNewsHub.com - All rights reserved

  • bitcoinBitcoin(BTC)$8,152.26-0.70%
  • ethereumEthereum(ETH)$175.30-1.63%
  • rippleXRP(XRP)$0.252799-0.58%
  • bitcoin-cashBitcoin Cash(BCH)$242.68-2.16%
  • tetherTether(USDT)$1.000.27%
  • litecoinLitecoin(LTC)$55.01-1.92%
  • eosEOS(EOS)$3.11-2.39%
  • binance-coinBinance Coin(BNB)$18.56-2.84%
  • cardanoCardano(ADA)$0.042556-2.10%
  • stellarStellar(XLM)$0.064655-3.04%
  • tronTRON(TRX)$0.016891-2.25%
  • moneroMonero(XMR)$58.64-0.32%
  • neoNEO(NEO)$11.682.51%
  • iotaIOTA(MIOTA)$0.245122-1.96%
  • dashDash(DASH)$65.431.15%
  • nemNEM(XEM)$0.039494-0.75%