home.social

#coinminer — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #coinminer, aggregated by home.social.

fetched live
  1. Analysis of #Koske #miner.

    It is an AI-generated #Linux #malware which was hidden in images with pandas. It supports wide variety of coinminers for various cryptocurrencies and for GPU and different CPU architectures. Its another component, #rootkit #hideproc, tries to hide the Koske miner from file listings and processes.

    malwarelab.eu/posts/koske-pand

    Video from #anyrun analysis:

    youtube.com/watch?v=1OSPp996XQ4

    #koskeminer #coinminer #blueteam #cybersecurity #dfir #malwareanalysis #infosec #reverseengineering

  2. Supershell Malware Being Distributed to Linux SSH Servers

    A Chinese-developed Go-based backdoor called Supershell is targeting poorly managed Linux SSH servers. The malware, which supports multiple platforms, primarily functions as a reverse shell for remote system control. Attackers use dictionary attacks from various IP addresses to gain access, then install Supershell directly or via a downloader script. The malware is downloaded from web and FTP servers. While Supershell is the initial payload for control hijacking, XMRig Monero CoinMiners are often installed alongside it, suggesting cryptocurrency mining as the ultimate goal. To protect against such attacks, administrators should use strong passwords, update systems regularly, and implement security measures like firewalls.

    Pulse ID: 66ed5aecd1c4b20f7441ddef
    Pulse Link: otx.alienvault.com/pulse/66ed5
    Pulse Author: AlienVault
    Created: 2024-09-20 11:22:20

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Chinese #CoinMiner #CyberSecurity #InfoSec #Linux #Malware #OTX #OpenThreatExchange #Password #Passwords #RAT #SSH #Word #bot #cryptocurrency #AlienVault

  3. #Typosquat alert: Someone set up a #fake site that mimics Sophos branding on Sopbos[.]com and that site delivers a #malware #coinminer installer called SophosInstaller.exe

    If you work on a team with a #domain #reputation service or feature, please mark that domain as #malicious.

    Let's all work to render this kind of garbage, and their domain registration, utterly useless. #FAFO

  4. Some of the final payloads overlap with previously-reported threats, such as #Truebot (#downloader, often linked to Cl0p #ransomware), #Buhti (ransomware), #MoneroOcean (a #coinminer, discussed here: news.sophos.com/en-us/2021/12/), and #Mirai (a #botnet #worm).

    One such example of a #miner, shown in the screenshot below, details the commands to terminate the processes and services used by other, competing malicious miners before launching their own #Monero (#XMR) mining software. This cynical form of 'capture the flag' is commonplace behavior among the threat actor groups who deploy and maintain hostile miners.

    5/6

  5. I've come across this interesting article by AhnLab about how SHC is being used to deploy malicious payloads on GNU/Linux systems: "Shc Linux Malware Installing CoinMiner".

    asec.ahnlab.com/en/45182/

    A nice reason to spend some time on this as follows in this thread.

    #ThreatIntelligence #Mitre #T1496 #GNU #Linux #Coinminer

  6. Eine Spionage-Malware der wohl staatlich finanzierten Turla-Gang setzt auf Dropbox zum Datenklau. In einem anderen Fall verschleierte Coin-Mining Schlimmeres.
    APT-Gruppen: Turla und Co. tarnen Angriffe durch scheinbar harmlose Aktivitäten
  7. Uuund ein weiterer Antrag auf Förderung der abgelehnt wurde. An manchen Tagen fühlt es sich so an als wäre alles oberhalb von Fussball oder Schützenverein in #Unna uninteressant. Wir machen dennoch weiter bis uns das Geld ausgeht. Plan B: wir verteilen #coinminer USB Sticks😎

  8. CW: Rant

    Little bro just called me and told me he has some #coinminer software on his #Windows computer.
    I hate proprietary systems SO much. One of the few things that make me really really aggressive.