home.social

#securityawareness — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #securityawareness, aggregated by home.social.

fetched live
  1. How to Stay Protected

    XMRig Malware Campaigns Target Businesses

    Cybersecurity threats continue to evolve, and one of the most persistent threats facing businesses today involves cybercriminals abusing the popular XMRig mining software. While XMRig is a legitimate, open-source cryptocurrency miner used by many enthusiasts to mine Monero (XMR), attackers frequently modify or secretly install it on corporate computers to generate profits without the owner’s knowledge.

    In this article, we’ll explain how XMRig is being misused in corporate environments, the risks to businesses, how these attacks work, and the best practices to prevent them.

    What Is XMRig?

    XMRig is a free and open-source CPU and GPU miner designed primarily for mining Monero (XMR). It is widely respected within the cryptocurrency community because it is efficient, actively maintained, and available for Windows, Linux, and macOS.

    By itself, XMRig is not malware. However, cybercriminals often bundle modified versions of XMRig with malicious software or deploy it after compromising a computer.

    Why Are Businesses Being Targeted?

    Corporate environments provide an attractive opportunity for attackers because they often contain:

    • High-performance desktop computers
    • Powerful servers
    • Multiple workstations
    • Cloud infrastructure
    • Continuous internet connectivity

    Instead of mining cryptocurrency on their own hardware, attackers infect company devices and secretly use the organisation’s computing power.

    The result is free cryptocurrency mining at the company’s expense.

    How XMRig Malware Gets Installed

    Most unauthorised XMRig installations begin after another security weakness has already been exploited.

    Common infection methods include:

    • Phishing emails containing malicious attachments
    • Fake software downloads
    • Exploitation of unpatched vulnerabilities
    • Weak Remote Desktop Protocol (RDP) passwords
    • Stolen administrator credentials
    • Trojan malware that downloads additional payloads

    Once attackers gain access, they silently install XMRig and configure it to connect to their own mining pools.

    Warning Signs of an XMRig Infection

    Many organisations discover mining malware only after performance problems become noticeable.

    Common symptoms include:

    • Constantly high CPU usage
    • Increased electricity consumption
    • Slow computers
    • Loud cooling fans
    • Servers running hotter than normal
    • Unknown scheduled tasks
    • Unexpected outbound network traffic
    • Security software being disabled

    Some attackers even configure XMRig to stop mining whenever a user opens Task Manager, making detection more difficult.

    Business Impact

    Although cryptojacking usually does not encrypt files like ransomware, it can still cause significant operational issues.

    Potential consequences include:

    Reduced Productivity

    Employees experience slower computers, affecting daily work.

    Higher Operating Costs

    Mining consumes CPU resources and electricity around the clock.

    Hardware Wear

    Continuous high CPU usage can shorten the lifespan of processors, cooling systems, and power supplies.

    Security Risks

    An XMRig infection often indicates that attackers already have unauthorised access to the network, meaning sensitive business data may also be at risk.

    How Organisations Can Protect Themselves

    Preventing cryptojacking requires multiple layers of security.

    Keep Systems Updated

    Install security updates for Windows, Linux, browsers, and all business software as soon as practical.

    Use Endpoint Protection

    Modern antivirus and endpoint detection solutions can identify suspicious mining behaviour before it becomes widespread.

    Enable Multi-Factor Authentication

    Protect administrator accounts and remote access services with MFA wherever possible.

    Monitor CPU Usage

    Investigate unexplained spikes in processor utilisation, especially outside business hours.

    Restrict Administrative Privileges

    Limit local administrator permissions to reduce the impact of compromised accounts.

    Educate Employees

    Regular cybersecurity awareness training helps staff recognise phishing emails and other social engineering attacks.

    Is XMRig Dangerous?

    The software itself is completely legitimate.

    The danger comes from unauthorised installation and misuse by attackers.

    Many security vendors detect unauthorised XMRig deployments because they are commonly associated with cryptojacking campaigns rather than because the software itself is malicious.

    Best Practices for IT Teams

    Organisations should adopt a proactive security strategy by:

    • Regularly auditing endpoints
    • Monitoring unusual network connections
    • Reviewing scheduled tasks and startup entries
    • Enforcing least-privilege access
    • Conducting vulnerability scans
    • Backing up critical business data
    • Implementing continuous security monitoring

    Early detection significantly reduces the financial and operational impact of mining malware.

    Final Thoughts

    Cryptocurrency mining software like XMRig serves legitimate purposes for individuals and organisations that choose to mine digital assets. However, when cybercriminals secretly deploy XMRig on corporate systems, it becomes part of a cryptojacking attack that wastes resources, increases costs, and may signal a broader security compromise.

    Businesses should combine strong cybersecurity practices, employee awareness, regular patching, and continuous monitoring to minimise the risk of unauthorised mining software running within their networks.

    By understanding how these attacks operate and responding quickly to suspicious activity, organisations can better protect their infrastructure, maintain productivity, and reduce the likelihood of future compromises.

    Frequently Asked Questions

    Is XMRig malware?

    No. XMRig is legitimate open-source cryptocurrency mining software. It only becomes part of malicious activity when attackers install it without permission.

    What cryptocurrency does XMRig mine?

    It is primarily designed to mine Monero (XMR) using the RandomX algorithm.

    Can antivirus detect XMRig?

    Many security products detect unauthorised XMRig installations because they are commonly used in cryptojacking attacks.

    How can I tell if my computer is mining cryptocurrency?

    Persistent high CPU usage, overheating, increased fan noise, slow performance, and unexplained network connections can all indicate possible cryptojacking.

    #Technology #ai #businessSecurity #corporateSecurity #cpuMining #cryptoMalware #cryptocurrencyMining #cryptojacking #cyberSecurity #cyberThreats #cyberSecurity #cybersecurity #dataProtection #endpointSecurity #enterpriseCybersecurity #ITSecurity #LinuxSecurity #malwareDetection #malwareProtection #miningMalware #Monero #MoneroMiner #MoneroMining #networkSecurity #phishingAttacks #RandomX #ransomware #security #securityAwareness #serverSecurity #WindowsSecurity #XMRig #XMRigMalware #XMRigMiner
  2. When you‘re at a conference hosted by an IT Security Industry Association… and nearly no one uses a privacy screen for their laptop.

    #Layer8 #HumanThreats #SecurityAwareness

  3. Waarschuwing: nep-CAPTCHA's - ook voor MacOS!

    In mijn vorige toot schreef ik dat nep-CAPTCHA's (met ClickFix aanvallen) ook denkbaar zijn voor andere besturingssystemen dan Windows.

    Zojuist zag ik in een toot van Kevin Beaumont (cyberplace.social/@GossiTheDog) dat Julia Métraux (in bsky.app/profile/juliametraux.), eveneens op Gizmodo, een nep-CAPTCHA bestemd voor MacOS had gespot, waarvan zij een screenshot publiceerde.

    In die screenshot (die ik hieronder gekopieerd heb) ziet u hoe deze MacOS variant er uit zag.

    Nogmaals, TRAP HIER NIET IN!

    #ClickFix #Malware #Awareness #SecurityAwareness #InfoSec #BigTechIsEvil #CAPTCHA

  4. Waarschuwing: nep-CAPTCHA's

    CAPTCHA-vensters, meestal met een aantal plaatjes er in waarvan je enkele, die aan gegeven criteria voeldoen, moet aanvinken, zijn bedoeld om te voorkomen dat "bots" of "robots" webpagina's uitlezen.

    In infosec.exchange/@briankrebs/1 meldt Brian Krebs (@briankrebs ) een nep-CAPTCHA op de Gizmodo website (zie plaatje hieronder, info in Alt text).

    Die nep-CAPTCHA vraagt u om onzichtbare tekst (die instructies bevat) naar het klembord te kopiëren, dat te plakken in een "terminal" of "command prompt" venster en dat uit te voeren. Daardoor wordt aanvullende kwaadaardige software gedownload en gestart.

    Dat dit een "ClickFix" aanval wordt genoemd hoeft u niet te onthouden, wel dat CAPTCHA's met onduidelijke instructies gevaarlijk zijn!

    Onderstaande is voor Windows, maar vergelijkbare CAPTCHA's zijn denkbaar voor MacOS, Linux, Android en iOS/iPadOS.

    TRAP ER NIET IN!

    Terzijde: "echte" CAPTCHA's zijn afschuwelijk: o.a. slechtziende mensen worden buitengesloten en virus/phishing scanners kunnen webpagina's niet analyseren. Bovendien vormen zij een inbreuk op uw privacy (veel CAPTCHA's komen van Google servers, waardoor Google weet dat u de pagina bezoekt) en u helpt hiermee AI te trainen.

    #ClickFix #Malware #Awareness #SecurityAwareness #InfoSec #BigTechIsEvil #CAPTCHA

  5. Your phishing program has great metrics. Your employees are still clicking.
    At BSides312, Mr. Sprawl is sharing a proven blueprint for phishing programs that actually change behavior. One startup went from a 40% click rate to under 10% in a year. No magic tool. Just a better approach.
    Professional phisher. Social engineering enthusiast.
    May 16th. Chicago.
    🎟️ bsides312.org
    #BSides312 #InfoSec #CyberSecurity #Phishing #SocialEngineering #SecurityAwareness #Chicago

  6. Most phishing emails create urgency — your account is locked, a payment failed, something expires tonight. That urgency is the tell.

    Legitimate services don't pressure you into clicking links. If the email is pushing you to act fast, slow down. Verify through official channels, not the link in the message.

    #InfoSec #Cybersecurity #Phishing #SocialEngineering #SecurityAwareness #ThreatIntel

  7. 🪝 We've hooked another review 🪝

    This week, Aleksandra Scalco reviews 𝙋𝙝𝙞𝙨𝙝𝙞𝙣𝙜 𝙛𝙤𝙧 𝘼𝙣𝙨𝙬𝙚𝙧𝙨: 𝙍𝙞𝙨𝙠 𝙄𝙙𝙚𝙣𝙩𝙞𝙛𝙞𝙘𝙖𝙩𝙞𝙤𝙣 𝙖𝙣𝙙 𝙈𝙞𝙩𝙞𝙜𝙖𝙩𝙞𝙤𝙣 𝙎𝙩𝙧𝙖𝙩𝙚𝙜𝙞𝙚𝙨, an IET book authored by Terry Merz and Lawrence Shaw...

    📝 cybercanon.org/phishing-for-an

    #CybersecurityBooks #SecurityAwareness #Risk

  8. A Chinese national pretended to be U.S. engineers and researchers for almost five years, from 2017 to 2021, and walked away with sensitive aerospace and weapons development software from NASA, the Air Force, the Navy, and the Army. There was no hacking or breaking through firewalls. People simply emailed him what he asked for, because they believed he was someone they knew.

    This worries me more than any zero-day vulnerability. The NASA OIG reported that Song Wu asked for the same software several times without explaining why he needed it. Most people miss this kind of red flag because no one teaches them to spot it. We invest millions in technology controls but spend very little on training people to pause and think like a threat actor before sending information.

    Export controls are not only about legal compliance. They are also about human behavior. Your employees make export control decisions every day, often without realizing it.

    When was the last time your organization ran a spear-phishing simulation aimed at your researchers, not just your finance team?

    If your security awareness program doesn't cover identity deception and unusual software requests, it is not thorough enough.

    thehackernews.com/2026/04/nasa
    #Cybersecurity #NationalSecurity #Espionage #SecurityAwareness #InfoSec #security #privacy #cloud #infosec

  9. We told employees to "be suspicious" of links they needed for work. Now we're adding "be careful with AI" to the awareness curriculum. Teaching when to escalate works better than teaching what to fear.

    zeltser.com/ai-influence-aware

    #cybersecurity #AI #securityawareness #infosec

  10. When an AI tool recommends an action and an employee carries it out, audit logs capture a legitimate human decision. The AI's role disappears. Addressing that blind spot takes more than awareness training.

    zeltser.com/ai-influence-aware

    #cybersecurity #AI #securityawareness #infosec

  11. "Be suspicious of links" didn't change employee behavior, and "be careful with AI" won't either. A tool that earns trust every day can't be countered with general caution. Escalation procedures and closing the audit trail gap address what vigilance training can't.

    zeltser.com/ai-influence-aware

    #cybersecurity #infosec #AI #securityawareness

  12. ⚛ Review Day! ⚛

    Thomas Laugle provides a "niche" recommendation for Dr. Rogayeh Tabrizi's 𝘽𝙚𝙝𝙖𝙫𝙞𝙤𝙧𝙖𝙡 𝘼𝙄: 𝙐𝙣𝙡𝙚𝙖𝙨𝙝 𝘿𝙚𝙘𝙞𝙨𝙞𝙤𝙣 𝙈𝙖𝙠𝙞𝙣𝙜 𝙬𝙞𝙩𝙝 𝘿𝙖𝙩𝙖

    ✍️ Read Thomas' thorough analysis: cybercanon.org/behavioral-ai-u

    #CybersecurityBooks #AISecurity #GRC #SecurityAwareness

  13. Information Security terms that sound fake but aren’t:
    “Watering Hole attack.”

    Which sounds like wildlife photography but actually means attackers waiting for users to visit a compromised site.

    #CyberSecurity #ThreatIntel #SecurityAwareness #SecurityTermsThatSoundFake

  14. 🎤 𝗜𝗻𝘁𝗲𝗿𝘃𝗶𝗲𝘄: 𝗙𝗶𝗿𝗲𝘄𝗮𝗹𝗹 𝗠𝗲𝗻𝘀𝗰𝗵 | #DFNmitteilungen

    #SecurityAwareness ist ein zentraler Baustein der #informationssicherheit.
    🔹 Doch wie lassen sich Mitarbeitende & Studierende nachhaltig sensibilisieren? 🔹 Welchen Nutzen haben Security-Awareness-Schulungen?
    🔹 Und welche Rolle spielt der Mensch bei Cyberangriffen?

    💬 Die Antworten hat Prof. Dr.-Ing. Sebastian Schinzel
    @seecurity von der FH Münster.
    👉 Lesen Sie jetzt das Interview: dfn.de/firewall-mensch/

  15. Wie sollen Menschen für Datenschutz und Datensicherheit sensibilisiert werden, wenn Kommunen, Behörden, Polizei, Banken etc. mit schlechtem Beispiel vorangehen und mit zunehmender Tendenz TikTok, WhatsApp, fragwürdige Chatbots (KI), X, Facebook & Co. für ihre Kommunikation und Außendarstellung nutzen? Eins der Gegenargumente derer, die sensibilisiert werden sollen lautet dann zu Recht: "Wenn Polizei, Banken und Kommunen usw. das nutzen, kann mir oder unserem Unternehmen das doch auch nicht schaden..."

    #datenschutz #datensicherheit #awareness #securityawareness #polizei #banken #kommunen #unternehmen #behoerden #tiktok #facebook #x