home.social

#moneroocean — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #moneroocean, aggregated by home.social.

  1. Some of the final payloads overlap with previously-reported threats, such as #Truebot (#downloader, often linked to Cl0p #ransomware), #Buhti (ransomware), #MoneroOcean (a #coinminer, discussed here: news.sophos.com/en-us/2021/12/), and #Mirai (a #botnet #worm).

    One such example of a #miner, shown in the screenshot below, details the commands to terminate the processes and services used by other, competing malicious miners before launching their own #Monero (#XMR) mining software. This cynical form of 'capture the flag' is commonplace behavior among the threat actor groups who deploy and maintain hostile miners.

    5/6