home.social

#coinminer — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #coinminer, aggregated by home.social.

fetched live
  1. Analysis of #Koske #miner.

    It is an AI-generated #Linux #malware which was hidden in images with pandas. It supports wide variety of coinminers for various cryptocurrencies and for GPU and different CPU architectures. Its another component, #rootkit #hideproc, tries to hide the Koske miner from file listings and processes.

    malwarelab.eu/posts/koske-pand

    Video from #anyrun analysis:

    youtube.com/watch?v=1OSPp996XQ4

    #koskeminer #coinminer #blueteam #cybersecurity #dfir #malwareanalysis #infosec #reverseengineering

  2. Analysis of #Koske #miner.

    It is an AI-generated #Linux #malware which was hidden in images with pandas. It supports wide variety of coinminers for various cryptocurrencies and for GPU and different CPU architectures. Its another component, #rootkit #hideproc, tries to hide the Koske miner from file listings and processes.

    malwarelab.eu/posts/koske-pand

    Video from #anyrun analysis:

    youtube.com/watch?v=1OSPp996XQ4

    #koskeminer #coinminer #blueteam #cybersecurity #dfir #malwareanalysis #infosec #reverseengineering

  3. Analysis of #Koske #miner.

    It is an AI-generated #Linux #malware which was hidden in images with pandas. It supports wide variety of coinminers for various cryptocurrencies and for GPU and different CPU architectures. Its another component, #rootkit #hideproc, tries to hide the Koske miner from file listings and processes.

    malwarelab.eu/posts/koske-pand

    Video from #anyrun analysis:

    youtube.com/watch?v=1OSPp996XQ4

    #koskeminer #coinminer #blueteam #cybersecurity #dfir #malwareanalysis #infosec #reverseengineering

  4. Analysis of #Koske #miner.

    It is an AI-generated #Linux #malware which was hidden in images with pandas. It supports wide variety of coinminers for various cryptocurrencies and for GPU and different CPU architectures. Its another component, #rootkit #hideproc, tries to hide the Koske miner from file listings and processes.

    malwarelab.eu/posts/koske-pand

    Video from #anyrun analysis:

    youtube.com/watch?v=1OSPp996XQ4

    #koskeminer #coinminer #blueteam #cybersecurity #dfir #malwareanalysis #infosec #reverseengineering

  5. Analysis of #Koske #miner.

    It is an AI-generated #Linux #malware which was hidden in images with pandas. It supports wide variety of coinminers for various cryptocurrencies and for GPU and different CPU architectures. Its another component, #rootkit #hideproc, tries to hide the Koske miner from file listings and processes.

    malwarelab.eu/posts/koske-pand

    Video from #anyrun analysis:

    youtube.com/watch?v=1OSPp996XQ4

    #koskeminer #coinminer #blueteam #cybersecurity #dfir #malwareanalysis #infosec #reverseengineering

  6. Supershell Malware Being Distributed to Linux SSH Servers

    A Chinese-developed Go-based backdoor called Supershell is targeting poorly managed Linux SSH servers. The malware, which supports multiple platforms, primarily functions as a reverse shell for remote system control. Attackers use dictionary attacks from various IP addresses to gain access, then install Supershell directly or via a downloader script. The malware is downloaded from web and FTP servers. While Supershell is the initial payload for control hijacking, XMRig Monero CoinMiners are often installed alongside it, suggesting cryptocurrency mining as the ultimate goal. To protect against such attacks, administrators should use strong passwords, update systems regularly, and implement security measures like firewalls.

    Pulse ID: 66ed5aecd1c4b20f7441ddef
    Pulse Link: otx.alienvault.com/pulse/66ed5
    Pulse Author: AlienVault
    Created: 2024-09-20 11:22:20

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Chinese #CoinMiner #CyberSecurity #InfoSec #Linux #Malware #OTX #OpenThreatExchange #Password #Passwords #RAT #SSH #Word #bot #cryptocurrency #AlienVault

  7. Supershell Malware Being Distributed to Linux SSH Servers

    A Chinese-developed Go-based backdoor called Supershell is targeting poorly managed Linux SSH servers. The malware, which supports multiple platforms, primarily functions as a reverse shell for remote system control. Attackers use dictionary attacks from various IP addresses to gain access, then install Supershell directly or via a downloader script. The malware is downloaded from web and FTP servers. While Supershell is the initial payload for control hijacking, XMRig Monero CoinMiners are often installed alongside it, suggesting cryptocurrency mining as the ultimate goal. To protect against such attacks, administrators should use strong passwords, update systems regularly, and implement security measures like firewalls.

    Pulse ID: 66ed5aecd1c4b20f7441ddef
    Pulse Link: otx.alienvault.com/pulse/66ed5
    Pulse Author: AlienVault
    Created: 2024-09-20 11:22:20

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Chinese #CoinMiner #CyberSecurity #InfoSec #Linux #Malware #OTX #OpenThreatExchange #Password #Passwords #RAT #SSH #Word #bot #cryptocurrency #AlienVault

  8. Supershell Malware Being Distributed to Linux SSH Servers

    A Chinese-developed Go-based backdoor called Supershell is targeting poorly managed Linux SSH servers. The malware, which supports multiple platforms, primarily functions as a reverse shell for remote system control. Attackers use dictionary attacks from various IP addresses to gain access, then install Supershell directly or via a downloader script. The malware is downloaded from web and FTP servers. While Supershell is the initial payload for control hijacking, XMRig Monero CoinMiners are often installed alongside it, suggesting cryptocurrency mining as the ultimate goal. To protect against such attacks, administrators should use strong passwords, update systems regularly, and implement security measures like firewalls.

    Pulse ID: 66ed5aecd1c4b20f7441ddef
    Pulse Link: otx.alienvault.com/pulse/66ed5
    Pulse Author: AlienVault
    Created: 2024-09-20 11:22:20

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Chinese #CoinMiner #CyberSecurity #InfoSec #Linux #Malware #OTX #OpenThreatExchange #Password #Passwords #RAT #SSH #Word #bot #cryptocurrency #AlienVault

  9. Supershell Malware Being Distributed to Linux SSH Servers

    A Chinese-developed Go-based backdoor called Supershell is targeting poorly managed Linux SSH servers. The malware, which supports multiple platforms, primarily functions as a reverse shell for remote system control. Attackers use dictionary attacks from various IP addresses to gain access, then install Supershell directly or via a downloader script. The malware is downloaded from web and FTP servers. While Supershell is the initial payload for control hijacking, XMRig Monero CoinMiners are often installed alongside it, suggesting cryptocurrency mining as the ultimate goal. To protect against such attacks, administrators should use strong passwords, update systems regularly, and implement security measures like firewalls.

    Pulse ID: 66ed5aecd1c4b20f7441ddef
    Pulse Link: otx.alienvault.com/pulse/66ed5
    Pulse Author: AlienVault
    Created: 2024-09-20 11:22:20

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Chinese #CoinMiner #CyberSecurity #InfoSec #Linux #Malware #OTX #OpenThreatExchange #Password #Passwords #RAT #SSH #Word #bot #cryptocurrency #AlienVault

  10. Supershell Malware Being Distributed to Linux SSH Servers

    A Chinese-developed Go-based backdoor called Supershell is targeting poorly managed Linux SSH servers. The malware, which supports multiple platforms, primarily functions as a reverse shell for remote system control. Attackers use dictionary attacks from various IP addresses to gain access, then install Supershell directly or via a downloader script. The malware is downloaded from web and FTP servers. While Supershell is the initial payload for control hijacking, XMRig Monero CoinMiners are often installed alongside it, suggesting cryptocurrency mining as the ultimate goal. To protect against such attacks, administrators should use strong passwords, update systems regularly, and implement security measures like firewalls.

    Pulse ID: 66ed5aecd1c4b20f7441ddef
    Pulse Link: otx.alienvault.com/pulse/66ed5
    Pulse Author: AlienVault
    Created: 2024-09-20 11:22:20

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Chinese #CoinMiner #CyberSecurity #InfoSec #Linux #Malware #OTX #OpenThreatExchange #Password #Passwords #RAT #SSH #Word #bot #cryptocurrency #AlienVault

  11. Binary Managed Object File (BMOF) Distributing XMRig CoinMiner

    This analysis explores the use of Binary Managed Object Files (BMOFs) in distributing XMRig CoinMiner. BMOFs, compiled versions of Managed Object Files, are not inherently malicious but can be exploited due to their ability to execute scripts. The report details how threat actors utilize BMOFs with Permanent Event Subscription for malware persistence. It describes an attack case attributed to BondNet, where malicious BMOFs are created and executed through mofcomp.exe after compromising SQL servers. The process involves deleting the hosts file, creating guest accounts, downloading VBE files, configuring RDP connections, and executing XMRig CoinMiner. The malware is detectable by AhnLab MDS under specific signatures in sandbox environments.

    Pulse ID: 66ea8e94a8ad8301bfc0f6c0
    Pulse Link: otx.alienvault.com/pulse/66ea8
    Pulse Author: AlienVault
    Created: 2024-09-18 08:25:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AhnLab #CoinMiner #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #RDP #SQL #bot #AlienVault

  12. Distribution of Zephyr CoinMiner Using Autoit

    A CoinMiner that mines Zephyr, the crytocurrency, is being distributed with Autoit, a popular tool for detecting and detecting cyber-thieves.

    Pulse ID: 65c0f246bb1492cec382cf73
    Pulse Link: otx.alienvault.com/pulse/65c0f
    Pulse Author: AlienVault
    Created: 2024-02-05 14:35:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #OTX #OpenThreatExchange #InfoSec #bot #CyberSecurity #CoinMiner #AlienVault

  13. Mimo CoinMiner and Mimus Ransomware Installed via Vulnerability Attacks

    A threat actor called Mimo has been exploiting vulnerabilities to install CoinMiners and other malware.

    Pulse ID: 65aa819dfed4b47f5aaebe94
    Pulse Link: otx.alienvault.com/pulse/65aa8
    Pulse Author: AlienVault
    Created: 2024-01-19 14:05:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #OTX #OpenThreatExchange #InfoSec #bot #CyberSecurity #RansomWare #Malware #Vulnerability #CoinMiner #AlienVault

  14. #Typosquat alert: Someone set up a #fake site that mimics Sophos branding on Sopbos[.]com and that site delivers a #malware #coinminer installer called SophosInstaller.exe

    If you work on a team with a #domain #reputation service or feature, please mark that domain as #malicious.

    Let's all work to render this kind of garbage, and their domain registration, utterly useless. #FAFO

  15. #Typosquat alert: Someone set up a #fake site that mimics Sophos branding on Sopbos[.]com and that site delivers a #malware #coinminer installer called SophosInstaller.exe

    If you work on a team with a #domain #reputation service or feature, please mark that domain as #malicious.

    Let's all work to render this kind of garbage, and their domain registration, utterly useless. #FAFO

  16. #Typosquat alert: Someone set up a #fake site that mimics Sophos branding on Sopbos[.]com and that site delivers a #malware #coinminer installer called SophosInstaller.exe

    If you work on a team with a #domain #reputation service or feature, please mark that domain as #malicious.

    Let's all work to render this kind of garbage, and their domain registration, utterly useless. #FAFO

  17. #Typosquat alert: Someone set up a #fake site that mimics Sophos branding on Sopbos[.]com and that site delivers a #malware #coinminer installer called SophosInstaller.exe

    If you work on a team with a #domain #reputation service or feature, please mark that domain as #malicious.

    Let's all work to render this kind of garbage, and their domain registration, utterly useless. #FAFO

  18. #Typosquat alert: Someone set up a #fake site that mimics Sophos branding on Sopbos[.]com and that site delivers a #malware #coinminer installer called SophosInstaller.exe

    If you work on a team with a #domain #reputation service or feature, please mark that domain as #malicious.

    Let's all work to render this kind of garbage, and their domain registration, utterly useless. #FAFO

  19. Some of the final payloads overlap with previously-reported threats, such as #Truebot (#downloader, often linked to Cl0p #ransomware), #Buhti (ransomware), #MoneroOcean (a #coinminer, discussed here: news.sophos.com/en-us/2021/12/), and #Mirai (a #botnet #worm).

    One such example of a #miner, shown in the screenshot below, details the commands to terminate the processes and services used by other, competing malicious miners before launching their own #Monero (#XMR) mining software. This cynical form of 'capture the flag' is commonplace behavior among the threat actor groups who deploy and maintain hostile miners.

    5/6

  20. Some of the final payloads overlap with previously-reported threats, such as #Truebot (#downloader, often linked to Cl0p #ransomware), #Buhti (ransomware), #MoneroOcean (a #coinminer, discussed here: news.sophos.com/en-us/2021/12/), and #Mirai (a #botnet #worm).

    One such example of a #miner, shown in the screenshot below, details the commands to terminate the processes and services used by other, competing malicious miners before launching their own #Monero (#XMR) mining software. This cynical form of 'capture the flag' is commonplace behavior among the threat actor groups who deploy and maintain hostile miners.

    5/6

  21. Some of the final payloads overlap with previously-reported threats, such as #Truebot (#downloader, often linked to Cl0p #ransomware), #Buhti (ransomware), #MoneroOcean (a #coinminer, discussed here: news.sophos.com/en-us/2021/12/), and #Mirai (a #botnet #worm).

    One such example of a #miner, shown in the screenshot below, details the commands to terminate the processes and services used by other, competing malicious miners before launching their own #Monero (#XMR) mining software. This cynical form of 'capture the flag' is commonplace behavior among the threat actor groups who deploy and maintain hostile miners.

    5/6

  22. Some of the final payloads overlap with previously-reported threats, such as #Truebot (#downloader, often linked to Cl0p #ransomware), #Buhti (ransomware), #MoneroOcean (a #coinminer, discussed here: news.sophos.com/en-us/2021/12/), and #Mirai (a #botnet #worm).

    One such example of a #miner, shown in the screenshot below, details the commands to terminate the processes and services used by other, competing malicious miners before launching their own #Monero (#XMR) mining software. This cynical form of 'capture the flag' is commonplace behavior among the threat actor groups who deploy and maintain hostile miners.

    5/6

  23. Some of the final payloads overlap with previously-reported threats, such as #Truebot (#downloader, often linked to Cl0p #ransomware), #Buhti (ransomware), #MoneroOcean (a #coinminer, discussed here: news.sophos.com/en-us/2021/12/), and #Mirai (a #botnet #worm).

    One such example of a #miner, shown in the screenshot below, details the commands to terminate the processes and services used by other, competing malicious miners before launching their own #Monero (#XMR) mining software. This cynical form of 'capture the flag' is commonplace behavior among the threat actor groups who deploy and maintain hostile miners.

    5/6

  24. I've come across this interesting article by AhnLab about how SHC is being used to deploy malicious payloads on GNU/Linux systems: "Shc Linux Malware Installing CoinMiner".

    asec.ahnlab.com/en/45182/

    A nice reason to spend some time on this as follows in this thread.

    #ThreatIntelligence #Mitre #T1496 #GNU #Linux #Coinminer

  25. I've come across this interesting article by AhnLab about how SHC is being used to deploy malicious payloads on GNU/Linux systems: "Shc Linux Malware Installing CoinMiner".

    asec.ahnlab.com/en/45182/

    A nice reason to spend some time on this as follows in this thread.

    #ThreatIntelligence #Mitre #T1496 #GNU #Linux #Coinminer

  26. I've come across this interesting article by AhnLab about how SHC is being used to deploy malicious payloads on GNU/Linux systems: "Shc Linux Malware Installing CoinMiner".

    asec.ahnlab.com/en/45182/

    A nice reason to spend some time on this as follows in this thread.

    #ThreatIntelligence #Mitre #T1496 #GNU #Linux #Coinminer

  27. I've come across this interesting article by AhnLab about how SHC is being used to deploy malicious payloads on GNU/Linux systems: "Shc Linux Malware Installing CoinMiner".

    asec.ahnlab.com/en/45182/

    A nice reason to spend some time on this as follows in this thread.

    #ThreatIntelligence #Mitre #T1496 #GNU #Linux #Coinminer

  28. I've come across this interesting article by AhnLab about how SHC is being used to deploy malicious payloads on GNU/Linux systems: "Shc Linux Malware Installing CoinMiner".

    asec.ahnlab.com/en/45182/

    A nice reason to spend some time on this as follows in this thread.

    #ThreatIntelligence #Mitre #T1496 #GNU #Linux #Coinminer

  29. Eine Spionage-Malware der wohl staatlich finanzierten Turla-Gang setzt auf Dropbox zum Datenklau. In einem anderen Fall verschleierte Coin-Mining Schlimmeres.
    APT-Gruppen: Turla und Co. tarnen Angriffe durch scheinbar harmlose Aktivitäten
  30. Uuund ein weiterer Antrag auf Förderung der abgelehnt wurde. An manchen Tagen fühlt es sich so an als wäre alles oberhalb von Fussball oder Schützenverein in #Unna uninteressant. Wir machen dennoch weiter bis uns das Geld ausgeht. Plan B: wir verteilen #coinminer USB Sticks😎

  31. CW: Rant

    Little bro just called me and told me he has some #coinminer software on his #Windows computer.
    I hate proprietary systems SO much. One of the few things that make me really really aggressive.