#cryptominers — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cryptominers, aggregated by home.social.
-
OPB: Oregon approves PGE’s 29.7% rate hike for data centers under landmark law. “The Oregon Public Utility Commission on Tuesday unanimously approved PGE’s 29.7% rate increase for data centers, cryptocurrency companies and large industrial energy users.”
https://rbfirehose.com/2026/07/11/opb-oregon-approves-pges-29-7-rate-hike-for-data-centers-under-landmark-law/ -
OPB: Oregon approves PGE’s 29.7% rate hike for data centers under landmark law. “The Oregon Public Utility Commission on Tuesday unanimously approved PGE’s 29.7% rate increase for data centers, cryptocurrency companies and large industrial energy users.”
https://rbfirehose.com/2026/07/11/opb-oregon-approves-pges-29-7-rate-hike-for-data-centers-under-landmark-law/ -
OPB: Oregon approves PGE’s 29.7% rate hike for data centers under landmark law. “The Oregon Public Utility Commission on Tuesday unanimously approved PGE’s 29.7% rate increase for data centers, cryptocurrency companies and large industrial energy users.”
https://rbfirehose.com/2026/07/11/opb-oregon-approves-pges-29-7-rate-hike-for-data-centers-under-landmark-law/ -
OPB: Oregon approves PGE’s 29.7% rate hike for data centers under landmark law. “The Oregon Public Utility Commission on Tuesday unanimously approved PGE’s 29.7% rate increase for data centers, cryptocurrency companies and large industrial energy users.”
https://rbfirehose.com/2026/07/11/opb-oregon-approves-pges-29-7-rate-hike-for-data-centers-under-landmark-law/ -
OPB: Oregon approves PGE’s 29.7% rate hike for data centers under landmark law. “The Oregon Public Utility Commission on Tuesday unanimously approved PGE’s 29.7% rate increase for data centers, cryptocurrency companies and large industrial energy users.”
https://rbfirehose.com/2026/07/11/opb-oregon-approves-pges-29-7-rate-hike-for-data-centers-under-landmark-law/ -
Deputy Home Minister: Over 75,000 Cryptominers Seized Since 2022 #crypto #cryptocurrency #cryptominers #cryptomining
https://www.lowyat.net/2026/398065/deputy-home-minister-over-75000-cryptominers-seized-since-2022/
-
Deputy Home Minister: Over 75,000 Cryptominers Seized Since 2022 #crypto #cryptocurrency #cryptominers #cryptomining
https://www.lowyat.net/2026/398065/deputy-home-minister-over-75000-cryptominers-seized-since-2022/
-
Deputy Home Minister: Over 75,000 Cryptominers Seized Since 2022 #crypto #cryptocurrency #cryptominers #cryptomining
https://www.lowyat.net/2026/398065/deputy-home-minister-over-75000-cryptominers-seized-since-2022/
-
Deputy Home Minister: Over 75,000 Cryptominers Seized Since 2022 #crypto #cryptocurrency #cryptominers #cryptomining
https://www.lowyat.net/2026/398065/deputy-home-minister-over-75000-cryptominers-seized-since-2022/
-
Deputy Home Minister: Over 75,000 Cryptominers Seized Since 2022 #crypto #cryptocurrency #cryptominers #cryptomining
https://www.lowyat.net/2026/398065/deputy-home-minister-over-75000-cryptominers-seized-since-2022/
-
TechSpot: Fake downloads of popular PC utilities are quietly installing crypto miners on enthusiast PCs. “The Windows Defender security team is alerting users with dedicated GPUs about scammers manipulating search engine results to distribute remote monitoring and cryptomining payloads. The hackers are manipulating not only search engine results but also AI chatbot responses.”
https://rbfirehose.com/2026/06/02/techspot-fake-downloads-of-popular-pc-utilities-are-quietly-installing-crypto-miners-on-enthusiast-pcs/ -
TechSpot: Fake downloads of popular PC utilities are quietly installing crypto miners on enthusiast PCs. “The Windows Defender security team is alerting users with dedicated GPUs about scammers manipulating search engine results to distribute remote monitoring and cryptomining payloads. The hackers are manipulating not only search engine results but also AI chatbot responses.”
https://rbfirehose.com/2026/06/02/techspot-fake-downloads-of-popular-pc-utilities-are-quietly-installing-crypto-miners-on-enthusiast-pcs/ -
TechSpot: Fake downloads of popular PC utilities are quietly installing crypto miners on enthusiast PCs. “The Windows Defender security team is alerting users with dedicated GPUs about scammers manipulating search engine results to distribute remote monitoring and cryptomining payloads. The hackers are manipulating not only search engine results but also AI chatbot responses.”
https://rbfirehose.com/2026/06/02/techspot-fake-downloads-of-popular-pc-utilities-are-quietly-installing-crypto-miners-on-enthusiast-pcs/ -
TechSpot: Fake downloads of popular PC utilities are quietly installing crypto miners on enthusiast PCs. “The Windows Defender security team is alerting users with dedicated GPUs about scammers manipulating search engine results to distribute remote monitoring and cryptomining payloads. The hackers are manipulating not only search engine results but also AI chatbot responses.”
https://rbfirehose.com/2026/06/02/techspot-fake-downloads-of-popular-pc-utilities-are-quietly-installing-crypto-miners-on-enthusiast-pcs/ -
TechSpot: Fake downloads of popular PC utilities are quietly installing crypto miners on enthusiast PCs. “The Windows Defender security team is alerting users with dedicated GPUs about scammers manipulating search engine results to distribute remote monitoring and cryptomining payloads. The hackers are manipulating not only search engine results but also AI chatbot responses.”
https://rbfirehose.com/2026/06/02/techspot-fake-downloads-of-popular-pc-utilities-are-quietly-installing-crypto-miners-on-enthusiast-pcs/ -
A bizarre new Linux malware can be found hiding in cute animal photos - That cute panda pic? It's actually a cryptominer https://www.techradar.com/pro/security/a-damaging-new-linux-malware-is-hiding-in-cute-animal-photos
That cute panda pic? It's actually a cryptominer #cybersecurity #Linux #malware #cuteimages #Pandas #cryptominers #LLMCoded -
A bizarre new Linux malware can be found hiding in cute animal photos - That cute panda pic? It's actually a cryptominer https://www.techradar.com/pro/security/a-damaging-new-linux-malware-is-hiding-in-cute-animal-photos
That cute panda pic? It's actually a cryptominer #cybersecurity #Linux #malware #cuteimages #Pandas #cryptominers #LLMCoded -
A bizarre new Linux malware can be found hiding in cute animal photos - That cute panda pic? It's actually a cryptominer https://www.techradar.com/pro/security/a-damaging-new-linux-malware-is-hiding-in-cute-animal-photos
That cute panda pic? It's actually a cryptominer #cybersecurity #Linux #malware #cuteimages #Pandas #cryptominers #LLMCoded -
A bizarre new Linux malware can be found hiding in cute animal photos - That cute panda pic? It's actually a cryptominer https://www.techradar.com/pro/security/a-damaging-new-linux-malware-is-hiding-in-cute-animal-photos
That cute panda pic? It's actually a cryptominer #cybersecurity #Linux #malware #cuteimages #Pandas #cryptominers #LLMCoded -
Malicious #VSCode extensions infect Windows with #cryptominers
The package names are:
Discord Rich Presence for VS Code - 189K Installs
Rojo – Roblox Studio Sync - 117K Installs
Solidity Compiler - 1.3K Installs
Claude AI
Golang Compiler
ChatGPT Agent for VSCode
HTML Obfuscator
Python Obfuscator for VSCode
Rust Compiler for VSCode
ExtensionTotal says it reported the malicious extensions to #Microsoft, but they are still available at the time of writing.
https://www.bleepingcomputer.com/news/security/malicious-vscode-extensions-infect-windows-with-cryptominers/ -
Malicious #VSCode extensions infect Windows with #cryptominers
The package names are:
Discord Rich Presence for VS Code - 189K Installs
Rojo – Roblox Studio Sync - 117K Installs
Solidity Compiler - 1.3K Installs
Claude AI
Golang Compiler
ChatGPT Agent for VSCode
HTML Obfuscator
Python Obfuscator for VSCode
Rust Compiler for VSCode
ExtensionTotal says it reported the malicious extensions to #Microsoft, but they are still available at the time of writing.
https://www.bleepingcomputer.com/news/security/malicious-vscode-extensions-infect-windows-with-cryptominers/ -
Malicious #VSCode extensions infect Windows with #cryptominers
The package names are:
Discord Rich Presence for VS Code - 189K Installs
Rojo – Roblox Studio Sync - 117K Installs
Solidity Compiler - 1.3K Installs
Claude AI
Golang Compiler
ChatGPT Agent for VSCode
HTML Obfuscator
Python Obfuscator for VSCode
Rust Compiler for VSCode
ExtensionTotal says it reported the malicious extensions to #Microsoft, but they are still available at the time of writing.
https://www.bleepingcomputer.com/news/security/malicious-vscode-extensions-infect-windows-with-cryptominers/ -
Malicious #VSCode extensions infect Windows with #cryptominers
The package names are:
Discord Rich Presence for VS Code - 189K Installs
Rojo – Roblox Studio Sync - 117K Installs
Solidity Compiler - 1.3K Installs
Claude AI
Golang Compiler
ChatGPT Agent for VSCode
HTML Obfuscator
Python Obfuscator for VSCode
Rust Compiler for VSCode
ExtensionTotal says it reported the malicious extensions to #Microsoft, but they are still available at the time of writing.
https://www.bleepingcomputer.com/news/security/malicious-vscode-extensions-infect-windows-with-cryptominers/ -
Malicious #VSCode extensions infect Windows with #cryptominers
The package names are:
Discord Rich Presence for VS Code - 189K Installs
Rojo – Roblox Studio Sync - 117K Installs
Solidity Compiler - 1.3K Installs
Claude AI
Golang Compiler
ChatGPT Agent for VSCode
HTML Obfuscator
Python Obfuscator for VSCode
Rust Compiler for VSCode
ExtensionTotal says it reported the malicious extensions to #Microsoft, but they are still available at the time of writing.
https://www.bleepingcomputer.com/news/security/malicious-vscode-extensions-infect-windows-with-cryptominers/ -
US accounts for over 40% of global Bitcoin hashrate: Report - Hashrate dominance continues to be debated due to the pseudonymous and g... - https://cointelegraph.com/news/us-accounts-over-40-percent-bitcoin-hashrate-2024 #hashratedominance #bitcoinhashrate #bitcoinmining #cryptomining #cryptominers #miningpools #mining #miners #btc
-
US accounts for over 40% of global Bitcoin hashrate: Report - Hashrate dominance continues to be debated due to the pseudonymous and g... - https://cointelegraph.com/news/us-accounts-over-40-percent-bitcoin-hashrate-2024 #hashratedominance #bitcoinhashrate #bitcoinmining #cryptomining #cryptominers #miningpools #mining #miners #btc
-
US accounts for over 40% of global Bitcoin hashrate: Report - Hashrate dominance continues to be debated due to the pseudonymous and g... - https://cointelegraph.com/news/us-accounts-over-40-percent-bitcoin-hashrate-2024 #hashratedominance #bitcoinhashrate #bitcoinmining #cryptomining #cryptominers #miningpools #mining #miners #btc
-
US accounts for over 40% of global Bitcoin hashrate: Report - Hashrate dominance continues to be debated due to the pseudonymous and g... - https://cointelegraph.com/news/us-accounts-over-40-percent-bitcoin-hashrate-2024 #hashratedominance #bitcoinhashrate #bitcoinmining #cryptomining #cryptominers #miningpools #mining #miners #btc
-
While crypto is dumb, this take on crypto is also dumb.
Arkansas officials halt cryptomine near LR Airbase due to national security concerns
https://katv.com/news/local/arkansas-officials-halt-cryptomine-near-lr-airbase-due-to-national-security-concerns-state-senator-ricky-hill-lonoke-county-judge-doug-erwin-cabot-mayor-ken-kincade-interstate-holdings-arkansas-blockchain-council-benjamin-smith-steven-landers-jr-lrafb
#crypto #cryptocurrency #cryptocult #cryptominer #cryptominers #arkansas #littlerock #ArkansasPolitics -
While crypto is dumb, this take on crypto is also dumb.
Arkansas officials halt cryptomine near LR Airbase due to national security concerns
https://katv.com/news/local/arkansas-officials-halt-cryptomine-near-lr-airbase-due-to-national-security-concerns-state-senator-ricky-hill-lonoke-county-judge-doug-erwin-cabot-mayor-ken-kincade-interstate-holdings-arkansas-blockchain-council-benjamin-smith-steven-landers-jr-lrafb
#crypto #cryptocurrency #cryptocult #cryptominer #cryptominers #arkansas #littlerock #ArkansasPolitics -
While crypto is dumb, this take on crypto is also dumb.
Arkansas officials halt cryptomine near LR Airbase due to national security concerns
https://katv.com/news/local/arkansas-officials-halt-cryptomine-near-lr-airbase-due-to-national-security-concerns-state-senator-ricky-hill-lonoke-county-judge-doug-erwin-cabot-mayor-ken-kincade-interstate-holdings-arkansas-blockchain-council-benjamin-smith-steven-landers-jr-lrafb
#crypto #cryptocurrency #cryptocult #cryptominer #cryptominers #arkansas #littlerock #ArkansasPolitics -
While crypto is dumb, this take on crypto is also dumb.
Arkansas officials halt cryptomine near LR Airbase due to national security concerns
https://katv.com/news/local/arkansas-officials-halt-cryptomine-near-lr-airbase-due-to-national-security-concerns-state-senator-ricky-hill-lonoke-county-judge-doug-erwin-cabot-mayor-ken-kincade-interstate-holdings-arkansas-blockchain-council-benjamin-smith-steven-landers-jr-lrafb
#crypto #cryptocurrency #cryptocult #cryptominer #cryptominers #arkansas #littlerock #ArkansasPolitics -
While crypto is dumb, this take on crypto is also dumb.
Arkansas officials halt cryptomine near LR Airbase due to national security concerns
https://katv.com/news/local/arkansas-officials-halt-cryptomine-near-lr-airbase-due-to-national-security-concerns-state-senator-ricky-hill-lonoke-county-judge-doug-erwin-cabot-mayor-ken-kincade-interstate-holdings-arkansas-blockchain-council-benjamin-smith-steven-landers-jr-lrafb
#crypto #cryptocurrency #cryptocult #cryptominer #cryptominers #arkansas #littlerock #ArkansasPolitics -
#Windows infected with backdoored #Linux #VM in #new phishing attacks
Using #virtualmachines to conduct attacks is nothing new, with #ransomware gangs and #cryptominers using them to stealthily perform malicious activity. However, threat actors commonly install these manually after they breach a network.
https://www.bleepingcomputer.com/news/security/windows-infected-with-backdoored-linux-vms-in-new-phishing-attacks/ #QEMU #ITSec -
#Windows infected with backdoored #Linux #VM in #new phishing attacks
Using #virtualmachines to conduct attacks is nothing new, with #ransomware gangs and #cryptominers using them to stealthily perform malicious activity. However, threat actors commonly install these manually after they breach a network.
https://www.bleepingcomputer.com/news/security/windows-infected-with-backdoored-linux-vms-in-new-phishing-attacks/ #QEMU #ITSec -
#Windows infected with backdoored #Linux #VM in #new phishing attacks
Using #virtualmachines to conduct attacks is nothing new, with #ransomware gangs and #cryptominers using them to stealthily perform malicious activity. However, threat actors commonly install these manually after they breach a network.
https://www.bleepingcomputer.com/news/security/windows-infected-with-backdoored-linux-vms-in-new-phishing-attacks/ #QEMU #ITSec -
#Windows infected with backdoored #Linux #VM in #new phishing attacks
Using #virtualmachines to conduct attacks is nothing new, with #ransomware gangs and #cryptominers using them to stealthily perform malicious activity. However, threat actors commonly install these manually after they breach a network.
https://www.bleepingcomputer.com/news/security/windows-infected-with-backdoored-linux-vms-in-new-phishing-attacks/ #QEMU #ITSec -
#Windows infected with backdoored #Linux #VM in #new phishing attacks
Using #virtualmachines to conduct attacks is nothing new, with #ransomware gangs and #cryptominers using them to stealthily perform malicious activity. However, threat actors commonly install these manually after they breach a network.
https://www.bleepingcomputer.com/news/security/windows-infected-with-backdoored-linux-vms-in-new-phishing-attacks/ #QEMU #ITSec -
What’s Next for Crypto Mining in Russia? Leaders Discuss Taxes and Legislation - Russia has been steadily moving towards full regulation of its crypto mining industry, as... - https://coingape.com/whats-next-for-crypto-mining-in-russia-leaders-discuss-taxes-and-legislation/ #24/7cryptocurrencynews #russiacryptomining #regulationnews #cryptominers
-
What’s Next for Crypto Mining in Russia? Leaders Discuss Taxes and Legislation - Russia has been steadily moving towards full regulation of its crypto mining industry, as... - https://coingape.com/whats-next-for-crypto-mining-in-russia-leaders-discuss-taxes-and-legislation/ #24/7cryptocurrencynews #russiacryptomining #regulationnews #cryptominers
-
What’s Next for Crypto Mining in Russia? Leaders Discuss Taxes and Legislation - Russia has been steadily moving towards full regulation of its crypto mining industry, as... - https://coingape.com/whats-next-for-crypto-mining-in-russia-leaders-discuss-taxes-and-legislation/ #24/7cryptocurrencynews #russiacryptomining #regulationnews #cryptominers
-
What’s Next for Crypto Mining in Russia? Leaders Discuss Taxes and Legislation - Russia has been steadily moving towards full regulation of its crypto mining industry, as... - https://coingape.com/whats-next-for-crypto-mining-in-russia-leaders-discuss-taxes-and-legislation/ #24/7cryptocurrencynews #russiacryptomining #regulationnews #cryptominers
-
Malaysia Loses Over $700 Million Worth of Electricity to Illegal Crypto Miners, Says Minister - According to a government minister, Malaysia lost $727 million worth of electricit... - https://news.bitcoin.com/malaysia-loses-over-700-million-worth-of-electricity-to-illegal-crypto-miners-says-minister/ #electricitytheft #cryptocurrency #cryptominers #mining
-
Malaysia Loses Over $700 Million Worth of Electricity to Illegal Crypto Miners, Says Minister - According to a government minister, Malaysia lost $727 million worth of electricit... - https://news.bitcoin.com/malaysia-loses-over-700-million-worth-of-electricity-to-illegal-crypto-miners-says-minister/ #electricitytheft #cryptocurrency #cryptominers #mining
-
Malaysia Loses Over $700 Million Worth of Electricity to Illegal Crypto Miners, Says Minister - According to a government minister, Malaysia lost $727 million worth of electricit... - https://news.bitcoin.com/malaysia-loses-over-700-million-worth-of-electricity-to-illegal-crypto-miners-says-minister/ #electricitytheft #cryptocurrency #cryptominers #mining
-
Malaysia Loses Over $700 Million Worth of Electricity to Illegal Crypto Miners, Says Minister - According to a government minister, Malaysia lost $727 million worth of electricit... - https://news.bitcoin.com/malaysia-loses-over-700-million-worth-of-electricity-to-illegal-crypto-miners-says-minister/ #electricitytheft #cryptocurrency #cryptominers #mining
-
Happy Friday everyone!
#Cryptominers and #CVE20173506 is featured in today's #readoftheday! Trend Micro takes us through a riveting tale where the protagonist, #WaterSigbin, abuses a vulnerability in Oracle WebLogic Servers. After exploitation, a Base64-encoded payload is run that drops the initial stage loader named "wireguard2-3.exe", which masquerades itself as a legitimate VPN technology to help with it's defense evasion. It also plays a role in getting the attack to the next stages which involve DLL-reflection, C2 communication, and finally the #XMRig cyrptominer.
Significant details that are included is a scheduled task created for Windows Defender exclusion, some discovery using WMI, and another scheduled task for persistence. As usual, I am not going to spoil it all, go and have a read for yourself! Enjoy and Happy Hunting!
Notable MITRE ATT&CK TTPs (thanks to the authors):
TA0001 - Initial Access
T1190 - Exploit Public-Facing ApplicationTA0002 - Execution
T1059.001 - Command and Scripting Interpreter: PowerShell
T1047 - Windows Management InstumentationTA0005 - Defense Evasion
T1620 - Reflective Code Loading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1562.001 - Impair Defenses: Disable or Modify ToolsTA0003 - Persistence
T1053.005 - Scheduled Task/Job: Scheduled TaskTA0011 - Command And Control
T1571 - Non-Standard Port
T1071 - Application Layer ProtocolTA0007 - Discovery
T1057 - Process Discovery
T1012 - Query RegistryExamining Water Sigbin's Infection Routine Leading to an XMRig Cryptominer
https://www.trendmicro.com/en_us/research/24/f/water-sigbin-xmrig.htmlIntel 471 #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #gethunting
-
Happy Friday everyone!
#Cryptominers and #CVE20173506 is featured in today's #readoftheday! Trend Micro takes us through a riveting tale where the protagonist, #WaterSigbin, abuses a vulnerability in Oracle WebLogic Servers. After exploitation, a Base64-encoded payload is run that drops the initial stage loader named "wireguard2-3.exe", which masquerades itself as a legitimate VPN technology to help with it's defense evasion. It also plays a role in getting the attack to the next stages which involve DLL-reflection, C2 communication, and finally the #XMRig cyrptominer.
Significant details that are included is a scheduled task created for Windows Defender exclusion, some discovery using WMI, and another scheduled task for persistence. As usual, I am not going to spoil it all, go and have a read for yourself! Enjoy and Happy Hunting!
Notable MITRE ATT&CK TTPs (thanks to the authors):
TA0001 - Initial Access
T1190 - Exploit Public-Facing ApplicationTA0002 - Execution
T1059.001 - Command and Scripting Interpreter: PowerShell
T1047 - Windows Management InstumentationTA0005 - Defense Evasion
T1620 - Reflective Code Loading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1562.001 - Impair Defenses: Disable or Modify ToolsTA0003 - Persistence
T1053.005 - Scheduled Task/Job: Scheduled TaskTA0011 - Command And Control
T1571 - Non-Standard Port
T1071 - Application Layer ProtocolTA0007 - Discovery
T1057 - Process Discovery
T1012 - Query RegistryExamining Water Sigbin's Infection Routine Leading to an XMRig Cryptominer
https://www.trendmicro.com/en_us/research/24/f/water-sigbin-xmrig.htmlIntel 471 #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #gethunting
-
Happy Friday everyone!
#Cryptominers and #CVE20173506 is featured in today's #readoftheday! Trend Micro takes us through a riveting tale where the protagonist, #WaterSigbin, abuses a vulnerability in Oracle WebLogic Servers. After exploitation, a Base64-encoded payload is run that drops the initial stage loader named "wireguard2-3.exe", which masquerades itself as a legitimate VPN technology to help with it's defense evasion. It also plays a role in getting the attack to the next stages which involve DLL-reflection, C2 communication, and finally the #XMRig cyrptominer.
Significant details that are included is a scheduled task created for Windows Defender exclusion, some discovery using WMI, and another scheduled task for persistence. As usual, I am not going to spoil it all, go and have a read for yourself! Enjoy and Happy Hunting!
Notable MITRE ATT&CK TTPs (thanks to the authors):
TA0001 - Initial Access
T1190 - Exploit Public-Facing ApplicationTA0002 - Execution
T1059.001 - Command and Scripting Interpreter: PowerShell
T1047 - Windows Management InstumentationTA0005 - Defense Evasion
T1620 - Reflective Code Loading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1562.001 - Impair Defenses: Disable or Modify ToolsTA0003 - Persistence
T1053.005 - Scheduled Task/Job: Scheduled TaskTA0011 - Command And Control
T1571 - Non-Standard Port
T1071 - Application Layer ProtocolTA0007 - Discovery
T1057 - Process Discovery
T1012 - Query RegistryExamining Water Sigbin's Infection Routine Leading to an XMRig Cryptominer
https://www.trendmicro.com/en_us/research/24/f/water-sigbin-xmrig.htmlIntel 471 #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #gethunting
-
Happy Friday everyone!
#Cryptominers and #CVE20173506 is featured in today's #readoftheday! Trend Micro takes us through a riveting tale where the protagonist, #WaterSigbin, abuses a vulnerability in Oracle WebLogic Servers. After exploitation, a Base64-encoded payload is run that drops the initial stage loader named "wireguard2-3.exe", which masquerades itself as a legitimate VPN technology to help with it's defense evasion. It also plays a role in getting the attack to the next stages which involve DLL-reflection, C2 communication, and finally the #XMRig cyrptominer.
Significant details that are included is a scheduled task created for Windows Defender exclusion, some discovery using WMI, and another scheduled task for persistence. As usual, I am not going to spoil it all, go and have a read for yourself! Enjoy and Happy Hunting!
Notable MITRE ATT&CK TTPs (thanks to the authors):
TA0001 - Initial Access
T1190 - Exploit Public-Facing ApplicationTA0002 - Execution
T1059.001 - Command and Scripting Interpreter: PowerShell
T1047 - Windows Management InstumentationTA0005 - Defense Evasion
T1620 - Reflective Code Loading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1562.001 - Impair Defenses: Disable or Modify ToolsTA0003 - Persistence
T1053.005 - Scheduled Task/Job: Scheduled TaskTA0011 - Command And Control
T1571 - Non-Standard Port
T1071 - Application Layer ProtocolTA0007 - Discovery
T1057 - Process Discovery
T1012 - Query RegistryExamining Water Sigbin's Infection Routine Leading to an XMRig Cryptominer
https://www.trendmicro.com/en_us/research/24/f/water-sigbin-xmrig.htmlIntel 471 #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #gethunting