#coinminer — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #coinminer, aggregated by home.social.
-
It is an AI-generated #Linux #malware which was hidden in images with pandas. It supports wide variety of coinminers for various cryptocurrencies and for GPU and different CPU architectures. Its another component, #rootkit #hideproc, tries to hide the Koske miner from file listings and processes.
https://malwarelab.eu/posts/koske-panda-ai/
Video from #anyrun analysis:
https://www.youtube.com/watch?v=1OSPp996XQ4
#koskeminer #coinminer #blueteam #cybersecurity #dfir #malwareanalysis #infosec #reverseengineering
-
It is an AI-generated #Linux #malware which was hidden in images with pandas. It supports wide variety of coinminers for various cryptocurrencies and for GPU and different CPU architectures. Its another component, #rootkit #hideproc, tries to hide the Koske miner from file listings and processes.
https://malwarelab.eu/posts/koske-panda-ai/
Video from #anyrun analysis:
https://www.youtube.com/watch?v=1OSPp996XQ4
#koskeminer #coinminer #blueteam #cybersecurity #dfir #malwareanalysis #infosec #reverseengineering
-
It is an AI-generated #Linux #malware which was hidden in images with pandas. It supports wide variety of coinminers for various cryptocurrencies and for GPU and different CPU architectures. Its another component, #rootkit #hideproc, tries to hide the Koske miner from file listings and processes.
https://malwarelab.eu/posts/koske-panda-ai/
Video from #anyrun analysis:
https://www.youtube.com/watch?v=1OSPp996XQ4
#koskeminer #coinminer #blueteam #cybersecurity #dfir #malwareanalysis #infosec #reverseengineering
-
It is an AI-generated #Linux #malware which was hidden in images with pandas. It supports wide variety of coinminers for various cryptocurrencies and for GPU and different CPU architectures. Its another component, #rootkit #hideproc, tries to hide the Koske miner from file listings and processes.
https://malwarelab.eu/posts/koske-panda-ai/
Video from #anyrun analysis:
https://www.youtube.com/watch?v=1OSPp996XQ4
#koskeminer #coinminer #blueteam #cybersecurity #dfir #malwareanalysis #infosec #reverseengineering
-
It is an AI-generated #Linux #malware which was hidden in images with pandas. It supports wide variety of coinminers for various cryptocurrencies and for GPU and different CPU architectures. Its another component, #rootkit #hideproc, tries to hide the Koske miner from file listings and processes.
https://malwarelab.eu/posts/koske-panda-ai/
Video from #anyrun analysis:
https://www.youtube.com/watch?v=1OSPp996XQ4
#koskeminer #coinminer #blueteam #cybersecurity #dfir #malwareanalysis #infosec #reverseengineering
-
Supershell Malware Being Distributed to Linux SSH Servers
A Chinese-developed Go-based backdoor called Supershell is targeting poorly managed Linux SSH servers. The malware, which supports multiple platforms, primarily functions as a reverse shell for remote system control. Attackers use dictionary attacks from various IP addresses to gain access, then install Supershell directly or via a downloader script. The malware is downloaded from web and FTP servers. While Supershell is the initial payload for control hijacking, XMRig Monero CoinMiners are often installed alongside it, suggesting cryptocurrency mining as the ultimate goal. To protect against such attacks, administrators should use strong passwords, update systems regularly, and implement security measures like firewalls.
Pulse ID: 66ed5aecd1c4b20f7441ddef
Pulse Link: https://otx.alienvault.com/pulse/66ed5aecd1c4b20f7441ddef
Pulse Author: AlienVault
Created: 2024-09-20 11:22:20Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Chinese #CoinMiner #CyberSecurity #InfoSec #Linux #Malware #OTX #OpenThreatExchange #Password #Passwords #RAT #SSH #Word #bot #cryptocurrency #AlienVault
-
Supershell Malware Being Distributed to Linux SSH Servers
A Chinese-developed Go-based backdoor called Supershell is targeting poorly managed Linux SSH servers. The malware, which supports multiple platforms, primarily functions as a reverse shell for remote system control. Attackers use dictionary attacks from various IP addresses to gain access, then install Supershell directly or via a downloader script. The malware is downloaded from web and FTP servers. While Supershell is the initial payload for control hijacking, XMRig Monero CoinMiners are often installed alongside it, suggesting cryptocurrency mining as the ultimate goal. To protect against such attacks, administrators should use strong passwords, update systems regularly, and implement security measures like firewalls.
Pulse ID: 66ed5aecd1c4b20f7441ddef
Pulse Link: https://otx.alienvault.com/pulse/66ed5aecd1c4b20f7441ddef
Pulse Author: AlienVault
Created: 2024-09-20 11:22:20Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Chinese #CoinMiner #CyberSecurity #InfoSec #Linux #Malware #OTX #OpenThreatExchange #Password #Passwords #RAT #SSH #Word #bot #cryptocurrency #AlienVault
-
Supershell Malware Being Distributed to Linux SSH Servers
A Chinese-developed Go-based backdoor called Supershell is targeting poorly managed Linux SSH servers. The malware, which supports multiple platforms, primarily functions as a reverse shell for remote system control. Attackers use dictionary attacks from various IP addresses to gain access, then install Supershell directly or via a downloader script. The malware is downloaded from web and FTP servers. While Supershell is the initial payload for control hijacking, XMRig Monero CoinMiners are often installed alongside it, suggesting cryptocurrency mining as the ultimate goal. To protect against such attacks, administrators should use strong passwords, update systems regularly, and implement security measures like firewalls.
Pulse ID: 66ed5aecd1c4b20f7441ddef
Pulse Link: https://otx.alienvault.com/pulse/66ed5aecd1c4b20f7441ddef
Pulse Author: AlienVault
Created: 2024-09-20 11:22:20Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Chinese #CoinMiner #CyberSecurity #InfoSec #Linux #Malware #OTX #OpenThreatExchange #Password #Passwords #RAT #SSH #Word #bot #cryptocurrency #AlienVault
-
Supershell Malware Being Distributed to Linux SSH Servers
A Chinese-developed Go-based backdoor called Supershell is targeting poorly managed Linux SSH servers. The malware, which supports multiple platforms, primarily functions as a reverse shell for remote system control. Attackers use dictionary attacks from various IP addresses to gain access, then install Supershell directly or via a downloader script. The malware is downloaded from web and FTP servers. While Supershell is the initial payload for control hijacking, XMRig Monero CoinMiners are often installed alongside it, suggesting cryptocurrency mining as the ultimate goal. To protect against such attacks, administrators should use strong passwords, update systems regularly, and implement security measures like firewalls.
Pulse ID: 66ed5aecd1c4b20f7441ddef
Pulse Link: https://otx.alienvault.com/pulse/66ed5aecd1c4b20f7441ddef
Pulse Author: AlienVault
Created: 2024-09-20 11:22:20Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Chinese #CoinMiner #CyberSecurity #InfoSec #Linux #Malware #OTX #OpenThreatExchange #Password #Passwords #RAT #SSH #Word #bot #cryptocurrency #AlienVault
-
Supershell Malware Being Distributed to Linux SSH Servers
A Chinese-developed Go-based backdoor called Supershell is targeting poorly managed Linux SSH servers. The malware, which supports multiple platforms, primarily functions as a reverse shell for remote system control. Attackers use dictionary attacks from various IP addresses to gain access, then install Supershell directly or via a downloader script. The malware is downloaded from web and FTP servers. While Supershell is the initial payload for control hijacking, XMRig Monero CoinMiners are often installed alongside it, suggesting cryptocurrency mining as the ultimate goal. To protect against such attacks, administrators should use strong passwords, update systems regularly, and implement security measures like firewalls.
Pulse ID: 66ed5aecd1c4b20f7441ddef
Pulse Link: https://otx.alienvault.com/pulse/66ed5aecd1c4b20f7441ddef
Pulse Author: AlienVault
Created: 2024-09-20 11:22:20Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Chinese #CoinMiner #CyberSecurity #InfoSec #Linux #Malware #OTX #OpenThreatExchange #Password #Passwords #RAT #SSH #Word #bot #cryptocurrency #AlienVault
-
Binary Managed Object File (BMOF) Distributing XMRig CoinMiner
This analysis explores the use of Binary Managed Object Files (BMOFs) in distributing XMRig CoinMiner. BMOFs, compiled versions of Managed Object Files, are not inherently malicious but can be exploited due to their ability to execute scripts. The report details how threat actors utilize BMOFs with Permanent Event Subscription for malware persistence. It describes an attack case attributed to BondNet, where malicious BMOFs are created and executed through mofcomp.exe after compromising SQL servers. The process involves deleting the hosts file, creating guest accounts, downloading VBE files, configuring RDP connections, and executing XMRig CoinMiner. The malware is detectable by AhnLab MDS under specific signatures in sandbox environments.
Pulse ID: 66ea8e94a8ad8301bfc0f6c0
Pulse Link: https://otx.alienvault.com/pulse/66ea8e94a8ad8301bfc0f6c0
Pulse Author: AlienVault
Created: 2024-09-18 08:25:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AhnLab #CoinMiner #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #RDP #SQL #bot #AlienVault
-
📬 PS4-Emulator installiert CoinMiner XMRig
#Malware #AhnLabSecurity #ASEC #CoinMiner #Playstation #PS4Emulator #XMRig https://sc.tarnkappe.info/2aa3fe -
📬 PS4-Emulator installiert CoinMiner XMRig
#Malware #AhnLabSecurity #ASEC #CoinMiner #Playstation #PS4Emulator #XMRig https://sc.tarnkappe.info/2aa3fe -
📬 PS4-Emulator installiert CoinMiner XMRig
#Malware #AhnLabSecurity #ASEC #CoinMiner #Playstation #PS4Emulator #XMRig https://sc.tarnkappe.info/2aa3fe -
📬 PS4-Emulator installiert CoinMiner XMRig
#Malware #AhnLabSecurity #ASEC #CoinMiner #Playstation #PS4Emulator #XMRig https://sc.tarnkappe.info/2aa3fe -
📬 PS4-Emulator installiert CoinMiner XMRig
#Malware #AhnLabSecurity #ASEC #CoinMiner #Playstation #PS4Emulator #XMRig https://sc.tarnkappe.info/2aa3fe -
Distribution of Zephyr CoinMiner Using Autoit
A CoinMiner that mines Zephyr, the crytocurrency, is being distributed with Autoit, a popular tool for detecting and detecting cyber-thieves.
Pulse ID: 65c0f246bb1492cec382cf73
Pulse Link: https://otx.alienvault.com/pulse/65c0f246bb1492cec382cf73
Pulse Author: AlienVault
Created: 2024-02-05 14:35:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#OTX #OpenThreatExchange #InfoSec #bot #CyberSecurity #CoinMiner #AlienVault
-
Mimo CoinMiner and Mimus Ransomware Installed via Vulnerability Attacks
A threat actor called Mimo has been exploiting vulnerabilities to install CoinMiners and other malware.
Pulse ID: 65aa819dfed4b47f5aaebe94
Pulse Link: https://otx.alienvault.com/pulse/65aa819dfed4b47f5aaebe94
Pulse Author: AlienVault
Created: 2024-01-19 14:05:16Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#OTX #OpenThreatExchange #InfoSec #bot #CyberSecurity #RansomWare #Malware #Vulnerability #CoinMiner #AlienVault
-
#Typosquat alert: Someone set up a #fake site that mimics Sophos branding on Sopbos[.]com and that site delivers a #malware #coinminer installer called SophosInstaller.exe
If you work on a team with a #domain #reputation service or feature, please mark that domain as #malicious.
Let's all work to render this kind of garbage, and their domain registration, utterly useless. #FAFO
-
#Typosquat alert: Someone set up a #fake site that mimics Sophos branding on Sopbos[.]com and that site delivers a #malware #coinminer installer called SophosInstaller.exe
If you work on a team with a #domain #reputation service or feature, please mark that domain as #malicious.
Let's all work to render this kind of garbage, and their domain registration, utterly useless. #FAFO
-
#Typosquat alert: Someone set up a #fake site that mimics Sophos branding on Sopbos[.]com and that site delivers a #malware #coinminer installer called SophosInstaller.exe
If you work on a team with a #domain #reputation service or feature, please mark that domain as #malicious.
Let's all work to render this kind of garbage, and their domain registration, utterly useless. #FAFO
-
#Typosquat alert: Someone set up a #fake site that mimics Sophos branding on Sopbos[.]com and that site delivers a #malware #coinminer installer called SophosInstaller.exe
If you work on a team with a #domain #reputation service or feature, please mark that domain as #malicious.
Let's all work to render this kind of garbage, and their domain registration, utterly useless. #FAFO
-
#Typosquat alert: Someone set up a #fake site that mimics Sophos branding on Sopbos[.]com and that site delivers a #malware #coinminer installer called SophosInstaller.exe
If you work on a team with a #domain #reputation service or feature, please mark that domain as #malicious.
Let's all work to render this kind of garbage, and their domain registration, utterly useless. #FAFO
-
Some of the final payloads overlap with previously-reported threats, such as #Truebot (#downloader, often linked to Cl0p #ransomware), #Buhti (ransomware), #MoneroOcean (a #coinminer, discussed here: https://news.sophos.com/en-us/2021/12/02/two-flavors-of-tor2mine-miner-dig-deep-into-networks-with-powershell-vbscript/), and #Mirai (a #botnet #worm).
One such example of a #miner, shown in the screenshot below, details the commands to terminate the processes and services used by other, competing malicious miners before launching their own #Monero (#XMR) mining software. This cynical form of 'capture the flag' is commonplace behavior among the threat actor groups who deploy and maintain hostile miners.
5/6
-
Some of the final payloads overlap with previously-reported threats, such as #Truebot (#downloader, often linked to Cl0p #ransomware), #Buhti (ransomware), #MoneroOcean (a #coinminer, discussed here: https://news.sophos.com/en-us/2021/12/02/two-flavors-of-tor2mine-miner-dig-deep-into-networks-with-powershell-vbscript/), and #Mirai (a #botnet #worm).
One such example of a #miner, shown in the screenshot below, details the commands to terminate the processes and services used by other, competing malicious miners before launching their own #Monero (#XMR) mining software. This cynical form of 'capture the flag' is commonplace behavior among the threat actor groups who deploy and maintain hostile miners.
5/6
-
Some of the final payloads overlap with previously-reported threats, such as #Truebot (#downloader, often linked to Cl0p #ransomware), #Buhti (ransomware), #MoneroOcean (a #coinminer, discussed here: https://news.sophos.com/en-us/2021/12/02/two-flavors-of-tor2mine-miner-dig-deep-into-networks-with-powershell-vbscript/), and #Mirai (a #botnet #worm).
One such example of a #miner, shown in the screenshot below, details the commands to terminate the processes and services used by other, competing malicious miners before launching their own #Monero (#XMR) mining software. This cynical form of 'capture the flag' is commonplace behavior among the threat actor groups who deploy and maintain hostile miners.
5/6
-
Some of the final payloads overlap with previously-reported threats, such as #Truebot (#downloader, often linked to Cl0p #ransomware), #Buhti (ransomware), #MoneroOcean (a #coinminer, discussed here: https://news.sophos.com/en-us/2021/12/02/two-flavors-of-tor2mine-miner-dig-deep-into-networks-with-powershell-vbscript/), and #Mirai (a #botnet #worm).
One such example of a #miner, shown in the screenshot below, details the commands to terminate the processes and services used by other, competing malicious miners before launching their own #Monero (#XMR) mining software. This cynical form of 'capture the flag' is commonplace behavior among the threat actor groups who deploy and maintain hostile miners.
5/6
-
Some of the final payloads overlap with previously-reported threats, such as #Truebot (#downloader, often linked to Cl0p #ransomware), #Buhti (ransomware), #MoneroOcean (a #coinminer, discussed here: https://news.sophos.com/en-us/2021/12/02/two-flavors-of-tor2mine-miner-dig-deep-into-networks-with-powershell-vbscript/), and #Mirai (a #botnet #worm).
One such example of a #miner, shown in the screenshot below, details the commands to terminate the processes and services used by other, competing malicious miners before launching their own #Monero (#XMR) mining software. This cynical form of 'capture the flag' is commonplace behavior among the threat actor groups who deploy and maintain hostile miners.
5/6
-
I've come across this interesting article by AhnLab about how SHC is being used to deploy malicious payloads on GNU/Linux systems: "Shc Linux Malware Installing CoinMiner".
https://asec.ahnlab.com/en/45182/
A nice reason to spend some time on this as follows in this thread.
-
I've come across this interesting article by AhnLab about how SHC is being used to deploy malicious payloads on GNU/Linux systems: "Shc Linux Malware Installing CoinMiner".
https://asec.ahnlab.com/en/45182/
A nice reason to spend some time on this as follows in this thread.
-
I've come across this interesting article by AhnLab about how SHC is being used to deploy malicious payloads on GNU/Linux systems: "Shc Linux Malware Installing CoinMiner".
https://asec.ahnlab.com/en/45182/
A nice reason to spend some time on this as follows in this thread.
-
I've come across this interesting article by AhnLab about how SHC is being used to deploy malicious payloads on GNU/Linux systems: "Shc Linux Malware Installing CoinMiner".
https://asec.ahnlab.com/en/45182/
A nice reason to spend some time on this as follows in this thread.
-
I've come across this interesting article by AhnLab about how SHC is being used to deploy malicious payloads on GNU/Linux systems: "Shc Linux Malware Installing CoinMiner".
https://asec.ahnlab.com/en/45182/
A nice reason to spend some time on this as follows in this thread.
-
Eine Spionage-Malware der wohl staatlich finanzierten Turla-Gang setzt auf Dropbox zum Datenklau. In einem anderen Fall verschleierte Coin-Mining Schlimmeres.
APT-Gruppen: Turla und Co. tarnen Angriffe durch scheinbar harmlose Aktivitäten -
Uuund ein weiterer Antrag auf Förderung der abgelehnt wurde. An manchen Tagen fühlt es sich so an als wäre alles oberhalb von Fussball oder Schützenverein in #Unna uninteressant. Wir machen dennoch weiter bis uns das Geld ausgeht. Plan B: wir verteilen #coinminer USB Sticks😎
-
CW: Rant
Little bro just called me and told me he has some #coinminer software on his #Windows computer.
I hate proprietary systems SO much. One of the few things that make me really really aggressive.