#xmrig — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #xmrig, aggregated by home.social.
-
How to Stay Protected
XMRig Malware Campaigns Target Businesses
Cybersecurity threats continue to evolve, and one of the most persistent threats facing businesses today involves cybercriminals abusing the popular XMRig mining software. While XMRig is a legitimate, open-source cryptocurrency miner used by many enthusiasts to mine Monero (XMR), attackers frequently modify or secretly install it on corporate computers to generate profits without the owner’s knowledge.
In this article, we’ll explain how XMRig is being misused in corporate environments, the risks to businesses, how these attacks work, and the best practices to prevent them.
What Is XMRig?
XMRig is a free and open-source CPU and GPU miner designed primarily for mining Monero (XMR). It is widely respected within the cryptocurrency community because it is efficient, actively maintained, and available for Windows, Linux, and macOS.
By itself, XMRig is not malware. However, cybercriminals often bundle modified versions of XMRig with malicious software or deploy it after compromising a computer.
Why Are Businesses Being Targeted?
Corporate environments provide an attractive opportunity for attackers because they often contain:
- High-performance desktop computers
- Powerful servers
- Multiple workstations
- Cloud infrastructure
- Continuous internet connectivity
Instead of mining cryptocurrency on their own hardware, attackers infect company devices and secretly use the organisation’s computing power.
The result is free cryptocurrency mining at the company’s expense.
How XMRig Malware Gets Installed
Most unauthorised XMRig installations begin after another security weakness has already been exploited.
Common infection methods include:
- Phishing emails containing malicious attachments
- Fake software downloads
- Exploitation of unpatched vulnerabilities
- Weak Remote Desktop Protocol (RDP) passwords
- Stolen administrator credentials
- Trojan malware that downloads additional payloads
Once attackers gain access, they silently install XMRig and configure it to connect to their own mining pools.
Warning Signs of an XMRig Infection
Many organisations discover mining malware only after performance problems become noticeable.
Common symptoms include:
- Constantly high CPU usage
- Increased electricity consumption
- Slow computers
- Loud cooling fans
- Servers running hotter than normal
- Unknown scheduled tasks
- Unexpected outbound network traffic
- Security software being disabled
Some attackers even configure XMRig to stop mining whenever a user opens Task Manager, making detection more difficult.
Business Impact
Although cryptojacking usually does not encrypt files like ransomware, it can still cause significant operational issues.
Potential consequences include:
Reduced Productivity
Employees experience slower computers, affecting daily work.
Higher Operating Costs
Mining consumes CPU resources and electricity around the clock.
Hardware Wear
Continuous high CPU usage can shorten the lifespan of processors, cooling systems, and power supplies.
Security Risks
An XMRig infection often indicates that attackers already have unauthorised access to the network, meaning sensitive business data may also be at risk.
How Organisations Can Protect Themselves
Preventing cryptojacking requires multiple layers of security.
Keep Systems Updated
Install security updates for Windows, Linux, browsers, and all business software as soon as practical.
Use Endpoint Protection
Modern antivirus and endpoint detection solutions can identify suspicious mining behaviour before it becomes widespread.
Enable Multi-Factor Authentication
Protect administrator accounts and remote access services with MFA wherever possible.
Monitor CPU Usage
Investigate unexplained spikes in processor utilisation, especially outside business hours.
Restrict Administrative Privileges
Limit local administrator permissions to reduce the impact of compromised accounts.
Educate Employees
Regular cybersecurity awareness training helps staff recognise phishing emails and other social engineering attacks.
Is XMRig Dangerous?
The software itself is completely legitimate.
The danger comes from unauthorised installation and misuse by attackers.
Many security vendors detect unauthorised XMRig deployments because they are commonly associated with cryptojacking campaigns rather than because the software itself is malicious.
Best Practices for IT Teams
Organisations should adopt a proactive security strategy by:
- Regularly auditing endpoints
- Monitoring unusual network connections
- Reviewing scheduled tasks and startup entries
- Enforcing least-privilege access
- Conducting vulnerability scans
- Backing up critical business data
- Implementing continuous security monitoring
Early detection significantly reduces the financial and operational impact of mining malware.
Final Thoughts
Cryptocurrency mining software like XMRig serves legitimate purposes for individuals and organisations that choose to mine digital assets. However, when cybercriminals secretly deploy XMRig on corporate systems, it becomes part of a cryptojacking attack that wastes resources, increases costs, and may signal a broader security compromise.
Businesses should combine strong cybersecurity practices, employee awareness, regular patching, and continuous monitoring to minimise the risk of unauthorised mining software running within their networks.
By understanding how these attacks operate and responding quickly to suspicious activity, organisations can better protect their infrastructure, maintain productivity, and reduce the likelihood of future compromises.
Frequently Asked Questions
Is XMRig malware?
No. XMRig is legitimate open-source cryptocurrency mining software. It only becomes part of malicious activity when attackers install it without permission.
What cryptocurrency does XMRig mine?
It is primarily designed to mine Monero (XMR) using the RandomX algorithm.
Can antivirus detect XMRig?
Many security products detect unauthorised XMRig installations because they are commonly used in cryptojacking attacks.
How can I tell if my computer is mining cryptocurrency?
Persistent high CPU usage, overheating, increased fan noise, slow performance, and unexplained network connections can all indicate possible cryptojacking.
#Technology #ai #businessSecurity #corporateSecurity #cpuMining #cryptoMalware #cryptocurrencyMining #cryptojacking #cyberSecurity #cyberThreats #cyberSecurity #cybersecurity #dataProtection #endpointSecurity #enterpriseCybersecurity #ITSecurity #LinuxSecurity #malwareDetection #malwareProtection #miningMalware #Monero #MoneroMiner #MoneroMining #networkSecurity #phishingAttacks #RandomX #ransomware #security #securityAwareness #serverSecurity #WindowsSecurity #XMRig #XMRigMalware #XMRigMiner -
How to Stay Protected
XMRig Malware Campaigns Target Businesses
Cybersecurity threats continue to evolve, and one of the most persistent threats facing businesses today involves cybercriminals abusing the popular XMRig mining software. While XMRig is a legitimate, open-source cryptocurrency miner used by many enthusiasts to mine Monero (XMR), attackers frequently modify or secretly install it on corporate computers to generate profits without the owner’s knowledge.
In this article, we’ll explain how XMRig is being misused in corporate environments, the risks to businesses, how these attacks work, and the best practices to prevent them.
What Is XMRig?
XMRig is a free and open-source CPU and GPU miner designed primarily for mining Monero (XMR). It is widely respected within the cryptocurrency community because it is efficient, actively maintained, and available for Windows, Linux, and macOS.
By itself, XMRig is not malware. However, cybercriminals often bundle modified versions of XMRig with malicious software or deploy it after compromising a computer.
Why Are Businesses Being Targeted?
Corporate environments provide an attractive opportunity for attackers because they often contain:
- High-performance desktop computers
- Powerful servers
- Multiple workstations
- Cloud infrastructure
- Continuous internet connectivity
Instead of mining cryptocurrency on their own hardware, attackers infect company devices and secretly use the organisation’s computing power.
The result is free cryptocurrency mining at the company’s expense.
How XMRig Malware Gets Installed
Most unauthorised XMRig installations begin after another security weakness has already been exploited.
Common infection methods include:
- Phishing emails containing malicious attachments
- Fake software downloads
- Exploitation of unpatched vulnerabilities
- Weak Remote Desktop Protocol (RDP) passwords
- Stolen administrator credentials
- Trojan malware that downloads additional payloads
Once attackers gain access, they silently install XMRig and configure it to connect to their own mining pools.
Warning Signs of an XMRig Infection
Many organisations discover mining malware only after performance problems become noticeable.
Common symptoms include:
- Constantly high CPU usage
- Increased electricity consumption
- Slow computers
- Loud cooling fans
- Servers running hotter than normal
- Unknown scheduled tasks
- Unexpected outbound network traffic
- Security software being disabled
Some attackers even configure XMRig to stop mining whenever a user opens Task Manager, making detection more difficult.
Business Impact
Although cryptojacking usually does not encrypt files like ransomware, it can still cause significant operational issues.
Potential consequences include:
Reduced Productivity
Employees experience slower computers, affecting daily work.
Higher Operating Costs
Mining consumes CPU resources and electricity around the clock.
Hardware Wear
Continuous high CPU usage can shorten the lifespan of processors, cooling systems, and power supplies.
Security Risks
An XMRig infection often indicates that attackers already have unauthorised access to the network, meaning sensitive business data may also be at risk.
How Organisations Can Protect Themselves
Preventing cryptojacking requires multiple layers of security.
Keep Systems Updated
Install security updates for Windows, Linux, browsers, and all business software as soon as practical.
Use Endpoint Protection
Modern antivirus and endpoint detection solutions can identify suspicious mining behaviour before it becomes widespread.
Enable Multi-Factor Authentication
Protect administrator accounts and remote access services with MFA wherever possible.
Monitor CPU Usage
Investigate unexplained spikes in processor utilisation, especially outside business hours.
Restrict Administrative Privileges
Limit local administrator permissions to reduce the impact of compromised accounts.
Educate Employees
Regular cybersecurity awareness training helps staff recognise phishing emails and other social engineering attacks.
Is XMRig Dangerous?
The software itself is completely legitimate.
The danger comes from unauthorised installation and misuse by attackers.
Many security vendors detect unauthorised XMRig deployments because they are commonly associated with cryptojacking campaigns rather than because the software itself is malicious.
Best Practices for IT Teams
Organisations should adopt a proactive security strategy by:
- Regularly auditing endpoints
- Monitoring unusual network connections
- Reviewing scheduled tasks and startup entries
- Enforcing least-privilege access
- Conducting vulnerability scans
- Backing up critical business data
- Implementing continuous security monitoring
Early detection significantly reduces the financial and operational impact of mining malware.
Final Thoughts
Cryptocurrency mining software like XMRig serves legitimate purposes for individuals and organisations that choose to mine digital assets. However, when cybercriminals secretly deploy XMRig on corporate systems, it becomes part of a cryptojacking attack that wastes resources, increases costs, and may signal a broader security compromise.
Businesses should combine strong cybersecurity practices, employee awareness, regular patching, and continuous monitoring to minimise the risk of unauthorised mining software running within their networks.
By understanding how these attacks operate and responding quickly to suspicious activity, organisations can better protect their infrastructure, maintain productivity, and reduce the likelihood of future compromises.
Frequently Asked Questions
Is XMRig malware?
No. XMRig is legitimate open-source cryptocurrency mining software. It only becomes part of malicious activity when attackers install it without permission.
What cryptocurrency does XMRig mine?
It is primarily designed to mine Monero (XMR) using the RandomX algorithm.
Can antivirus detect XMRig?
Many security products detect unauthorised XMRig installations because they are commonly used in cryptojacking attacks.
How can I tell if my computer is mining cryptocurrency?
Persistent high CPU usage, overheating, increased fan noise, slow performance, and unexplained network connections can all indicate possible cryptojacking.
#Technology #ai #businessSecurity #corporateSecurity #cpuMining #cryptoMalware #cryptocurrencyMining #cryptojacking #cyberSecurity #cyberThreats #cyberSecurity #cybersecurity #dataProtection #endpointSecurity #enterpriseCybersecurity #ITSecurity #LinuxSecurity #malwareDetection #malwareProtection #miningMalware #Monero #MoneroMiner #MoneroMining #networkSecurity #phishingAttacks #RandomX #ransomware #security #securityAwareness #serverSecurity #WindowsSecurity #XMRig #XMRigMalware #XMRigMiner -
Je viens de changer le bloc ventilateur/radiateur de mon #Framework Laptop 13, et le CPU n'a jamais été aussi froid!
85°C en pleine charge avec le Core Ultra 5 125H, c'est beaucoup mieux que les 105°C que j'avais avant.
J'ai enfin retrouvé les 4KH/s avec #xmrig.
-
So I was experimenting with #XMrig yesterday; was thinking of using my Ryzen 9 mini PC to do some #Monero mining. I noticed a status message that said something about the hash rate being limited because of lack of access to an "MSR Mod". Apparently the "fix" for this is to run xmrig as root and disable secure boot.
Call me paranoid, but that seems really suspicious. I aint giving no third party software root privileges.
-
So I was experimenting with #XMrig yesterday; was thinking of using my Ryzen 9 mini PC to do some #Monero mining. I noticed a status message that said something about the hash rate being limited because of lack of access to an "MSR Mod". Apparently the "fix" for this is to run xmrig as root and disable secure boot.
Call me paranoid, but that seems really suspicious. I aint giving no third party software root privileges.
-
Warning - If you run a #librewolf docker on #unraid then you are exposing yourself to #xmrig #crypomining #malware
Please be aware of this!
-
Warning - If you run a #librewolf docker on #unraid then you are exposing yourself to #xmrig #crypomining #malware
Please be aware of this!
-
Да, **P2Pool** — лучший вариант для майнинга Monero без необходимости доверять централизованным пулам. Он сочетает **децентрализацию, анонимность и устойчивость к цензуре**.
### **Почему P2Pool выгоден?**
✅ **Децентрализованный:** Нет админов, которые могут украсть выплаты или манипулировать наградами.
✅ **Низкие комиссии:** Всего **0.9%**, которые идут на поддержание сети.
✅ **Прямая выплата на кошелек:** Никаких минимальных балансов и задержек — монеты сразу на твоем XMR-адресе.
✅ **Приватность:** Не требует KYC, IP можно скрыть через Tor или VPN.### **Как начать без танцев с бубном?**
1. **Установи кошелек** (лучше GUI-кошелек от Monero или Feather Wallet).
2. **Скачай майнер** ([XMRig](https://xmrig.com) — лучший вариант).
3. **Настрой соединение с P2Pool**:
- **Адрес пула**: `127.0.0.1:37889` (локальный P2Pool-нода).
- **Твой XMR-кошелек в качестве логина**.
4. **Запусти P2Pool-ноду** ([инструкция](https://p2pool.io/#getting-started)).
5. **Запусти XMRig** и майнь без посредников!
⚡ **P2Pool — это как Биткойн-ноды, только для Monero:** полная автономность, никаких посредников и максимальная приватность.#Monero #XMR #CryptoMining #P2Pool #Privacy #Decentralization #NoKYC #Mining #AnonCrypto #XMRig
-
Security Week 2509: компьютерные игры с вредоносным кодом
Сразу две новости прошлой недели сообщают о новых случаях распространения компьютерных игр с вредоносным кодом внутри. Исследование специалистов «Лаборатории Касперского» разбирает масштабную вредоносную кампанию, в ходе которой на популярных торрент-трекерах распространялись версии игр со встроенной троянской программой. Заряженные дистрибутивы компьютерных игр распространялись на торрентах начиная с сентября 2024 года. В список зараженных игр входили BeamNG.drive, Garry’s Mod, Dyson Sphere Program, Universe Sandbox и Plutocracy, причем, по данным «Лаборатории Касперского», наибольшее число заражений пришлось на игру BeamNG.drive. Большинство атак зафиксировано на пользователей из России, но инциденты наблюдались также в Беларуси, Казахстане, Германии и Бразилии. Целью этой разовой кампании были относительно мощные игровые компьютеры, на которые устанавливался майнер криптовалюты.
-
StaryDobry ruins New Year’s Eve, delivering miner instead of presents – Source: securelist.com https://ciso2ciso.com/starydobry-ruins-new-years-eve-delivering-miner-instead-of-presents-source-securelist-com/ #rssfeedpostgeneratorecho #MalwareDescriptions #MalwareTechnologies #CyberSecurityNews #Financialthreats #Windowsmalware #Gamingmalware #securelistcom #spoofing #Malware #Torrent #Trojan #Miner #XMrig #DLL
-
StaryDobry ruins New Year’s Eve, delivering miner instead of presents – Source: securelist.com https://ciso2ciso.com/starydobry-ruins-new-years-eve-delivering-miner-instead-of-presents-source-securelist-com/ #rssfeedpostgeneratorecho #MalwareDescriptions #MalwareTechnologies #CyberSecurityNews #Financialthreats #Windowsmalware #Gamingmalware #securelistcom #spoofing #Malware #Torrent #Trojan #Miner #XMrig #DLL
-
📬 CrowdStrike-Phishing: Jobsuchende bekommen Crypto-Miner untergeschoben
#ITSicherheit #Malware #Crowdstrike #CrowdStrikePhishing #CryptoMiningMalware #Phishing #PhishingAngriff #XMRig https://sc.tarnkappe.info/83c4fd -
📬 CrowdStrike-Phishing: Jobsuchende bekommen Crypto-Miner untergeschoben
#ITSicherheit #Malware #Crowdstrike #CrowdStrikePhishing #CryptoMiningMalware #Phishing #PhishingAngriff #XMRig https://sc.tarnkappe.info/83c4fd -
Supply Chain Attack Hits Rspack, Vant npm Packages with Monero Miner – Source:hackread.com https://ciso2ciso.com/supply-chain-attack-hits-rspack-vant-npm-packages-with-monero-miner-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #cybersecurity #Vulnerability #CyberAttacks #CyberAttack #Hackread #security #malware #Monero #Python #XMRig #NPM
-
Supply Chain Attack Hits Rspack, Vant npm Packages with Monero Miner – Source:hackread.com https://ciso2ciso.com/supply-chain-attack-hits-rspack-vant-npm-packages-with-monero-miner-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #cybersecurity #Vulnerability #CyberAttacks #CyberAttack #Hackread #security #malware #Monero #Python #XMRig #NPM
-
Supply Chain Attack Hits Rspack, Vant npm Packages with Monero Miner https://hackread.com/supply-chain-attack-rspack-vant-npm-monero-miner/ #Cybersecurity #Vulnerability #CyberAttacks #CyberAttack #Security #Malware #Monero #Python #XMRig #NPM
-
Supply Chain Attack Hits Rspack, Vant npm Packages with Monero Miner https://hackread.com/supply-chain-attack-rspack-vant-npm-monero-miner/ #Cybersecurity #Vulnerability #CyberAttacks #CyberAttack #Security #Malware #Monero #Python #XMRig #NPM
-
Part 3 of my #cryptominer infection saga.
Being too lazy to secure my infected #prometheus container, I was looking for another way to combat it.
Killing it did now work because it's CnC was bringing it up in under a minute.My "fix" is inspired if I say so myself.
Is to run a cronjob to set nice setting to the lowest possible
(nice -n 19 xmrig)
This makes the #xmrig crapto miner at the least possible CPU priority.See if you can see on my attached performance chart, when it kicks in
😁
#infosec -
Hackers maken misbruik van docker api voor cryptojacking https://www.trendingtech.news/trending-news/2024/10/39932/hackers-maken-misbruik-van-docker-api-voor-cryptojacking #Docker #cryptojacking #cybersecurity #malware #XMRig #Trending #News #Nieuws
-
Thanks to (very patient) contributors, our new #xmrig container is now ready!
Works with CPU and/or CUDA.
https://github.com/metal3d/docker-xmrig/pkgs/container/xmrig/281208457?tag=v6.22.0
-
This is a destructive OPSEC failure.
PoC code is trivial to find along with a simple Censys query to uncover vulnerable hosts. The code itself supports a TXT file of URLs so....spray and pray method to find targets. Certain campaigns used #XMRig, GoThief, and backdoors like #Gh0stRAT and #PlugX.It should go without saying to not make your file servers open to the public but some didn't get the memo.
#HFS #CVE202423692 #ThreatIntel -
This is a destructive OPSEC failure.
PoC code is trivial to find along with a simple Censys query to uncover vulnerable hosts. The code itself supports a TXT file of URLs so....spray and pray method to find targets. Certain campaigns used #XMRig, GoThief, and backdoors like #Gh0stRAT and #PlugX.It should go without saying to not make your file servers open to the public but some didn't get the memo.
#HFS #CVE202423692 #ThreatIntel -
Happy Friday everyone!
#Cryptominers and #CVE20173506 is featured in today's #readoftheday! Trend Micro takes us through a riveting tale where the protagonist, #WaterSigbin, abuses a vulnerability in Oracle WebLogic Servers. After exploitation, a Base64-encoded payload is run that drops the initial stage loader named "wireguard2-3.exe", which masquerades itself as a legitimate VPN technology to help with it's defense evasion. It also plays a role in getting the attack to the next stages which involve DLL-reflection, C2 communication, and finally the #XMRig cyrptominer.
Significant details that are included is a scheduled task created for Windows Defender exclusion, some discovery using WMI, and another scheduled task for persistence. As usual, I am not going to spoil it all, go and have a read for yourself! Enjoy and Happy Hunting!
Notable MITRE ATT&CK TTPs (thanks to the authors):
TA0001 - Initial Access
T1190 - Exploit Public-Facing ApplicationTA0002 - Execution
T1059.001 - Command and Scripting Interpreter: PowerShell
T1047 - Windows Management InstumentationTA0005 - Defense Evasion
T1620 - Reflective Code Loading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1562.001 - Impair Defenses: Disable or Modify ToolsTA0003 - Persistence
T1053.005 - Scheduled Task/Job: Scheduled TaskTA0011 - Command And Control
T1571 - Non-Standard Port
T1071 - Application Layer ProtocolTA0007 - Discovery
T1057 - Process Discovery
T1012 - Query RegistryExamining Water Sigbin's Infection Routine Leading to an XMRig Cryptominer
https://www.trendmicro.com/en_us/research/24/f/water-sigbin-xmrig.htmlIntel 471 #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #gethunting
-
Happy Friday everyone!
#Cryptominers and #CVE20173506 is featured in today's #readoftheday! Trend Micro takes us through a riveting tale where the protagonist, #WaterSigbin, abuses a vulnerability in Oracle WebLogic Servers. After exploitation, a Base64-encoded payload is run that drops the initial stage loader named "wireguard2-3.exe", which masquerades itself as a legitimate VPN technology to help with it's defense evasion. It also plays a role in getting the attack to the next stages which involve DLL-reflection, C2 communication, and finally the #XMRig cyrptominer.
Significant details that are included is a scheduled task created for Windows Defender exclusion, some discovery using WMI, and another scheduled task for persistence. As usual, I am not going to spoil it all, go and have a read for yourself! Enjoy and Happy Hunting!
Notable MITRE ATT&CK TTPs (thanks to the authors):
TA0001 - Initial Access
T1190 - Exploit Public-Facing ApplicationTA0002 - Execution
T1059.001 - Command and Scripting Interpreter: PowerShell
T1047 - Windows Management InstumentationTA0005 - Defense Evasion
T1620 - Reflective Code Loading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1562.001 - Impair Defenses: Disable or Modify ToolsTA0003 - Persistence
T1053.005 - Scheduled Task/Job: Scheduled TaskTA0011 - Command And Control
T1571 - Non-Standard Port
T1071 - Application Layer ProtocolTA0007 - Discovery
T1057 - Process Discovery
T1012 - Query RegistryExamining Water Sigbin's Infection Routine Leading to an XMRig Cryptominer
https://www.trendmicro.com/en_us/research/24/f/water-sigbin-xmrig.htmlIntel 471 #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #gethunting
-
📬 PS4-Emulator installiert CoinMiner XMRig
#Malware #AhnLabSecurity #ASEC #CoinMiner #Playstation #PS4Emulator #XMRig https://sc.tarnkappe.info/2aa3fe -
📬 PS4-Emulator installiert CoinMiner XMRig
#Malware #AhnLabSecurity #ASEC #CoinMiner #Playstation #PS4Emulator #XMRig https://sc.tarnkappe.info/2aa3fe -
SonicWall warns of a cryptominer disguised as a Java Access Bridge installation installer package, but doesn't provide IOC. 🔗 https://blog.sonicwall.com/en-us/2024/04/cryptominer-poses-as-fake-java-utility/
-
SonicWall warns of a cryptominer disguised as a Java Access Bridge installation installer package, but doesn't provide IOC. 🔗 https://blog.sonicwall.com/en-us/2024/04/cryptominer-poses-as-fake-java-utility/
-
Exploitation of CVE-2024-27198 (9.8, disclosed on 04 March 2024 by JetBrains, has Proof of Concept, in KEV Catalog 07 March 2024: auth bypass in TeamCity) has been observed by Trend Micro to drop Jasmin ransomware, XMRig cryptocurrency miner, SparkRAT backdoor, and Cobalt Strike beacons. MITRE ATT&CK TTPs and IOC provided. 🔗 https://www.trendmicro.com/en_us/research/24/c/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware.html
#CVE_2024_27198 #KEV #CISA #JetBrains #TeamCity #vulnerability #eitw #activeexploitation #ransomware #threatintel #Jasmin #XMrig #cryptomining #SparkRAT #CobaltStrike #IOC #threatintel #proofofconcept
-
Exploitation of CVE-2024-27198 (9.8, disclosed on 04 March 2024 by JetBrains, has Proof of Concept, in KEV Catalog 07 March 2024: auth bypass in TeamCity) has been observed by Trend Micro to drop Jasmin ransomware, XMRig cryptocurrency miner, SparkRAT backdoor, and Cobalt Strike beacons. MITRE ATT&CK TTPs and IOC provided. 🔗 https://www.trendmicro.com/en_us/research/24/c/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware.html
#CVE_2024_27198 #KEV #CISA #JetBrains #TeamCity #vulnerability #eitw #activeexploitation #ransomware #threatintel #Jasmin #XMrig #cryptomining #SparkRAT #CobaltStrike #IOC #threatintel #proofofconcept
-
Mining Monero can be as simple or complicated as you want it to be.
-
Mining Monero can be as simple or complicated as you want it to be.
-
CPU Mining on a Raspberry Pi using #XMRig #cpumining #crypto
https://technical.izndgroup.com/2020/08/cpu-mining-on-raspberry-pi-xmrig.html
-
@kubikpixel Erinnert mich an so manche #malware die sich per non-persistence von Erkennung und Bekämpfung schützt.
#xmrig ohne sudo und mit geringster Priorität hat extrem schlechte #Hashrate aber langfristiger lohnt es sich für jene Cyberkriminelle unbemerkt weniger Rechenleistung zu 'stehlen' denn binnen weniger Stunden oder Tage von erkannt und von Systemen geworfen zu werden...
-
📬 Final Cut Pro kostenlos runterladen? Aber bitte ohne Malware!
#Malware #AdobePhotoshop #FinalCutPro #Kryptomining #LogicPro #Mac #macOS #Monero #ThePirateBay #torrent #XMRig #XProtect https://tarnkappe.info/artikel/malware/final-cut-pro-kostenlos-runterladen-aber-bitte-ohne-malware-265921.html -
📬 Final Cut Pro kostenlos runterladen? Aber bitte ohne Malware!
#Malware #AdobePhotoshop #FinalCutPro #Kryptomining #LogicPro #Mac #macOS #Monero #ThePirateBay #torrent #XMRig #XProtect https://tarnkappe.info/artikel/malware/final-cut-pro-kostenlos-runterladen-aber-bitte-ohne-malware-265921.html -
This article is confusing, as it seems to suggest that shc (shell script compiler) is the malware. shc is legitimate software (although I've never seen it used), it is just being used to obfuscate (and potentially bypass detection) shell scripts that download and install the #XMRig coinminer.
-
From a #ThreatIntelligence perspective, the #TTPs would be:
- #T1059.003: Command and Scripting Interpreter: Unix Shell. SHC payloads to be run still need a shell to be identified in the system and that the code inside the payload is, in fact, a shell script.
- #T1027.002: Obfuscated Files or Information: Software Packed with #SHC.
- #T1622: Debugger Evasion by using SHC with '-r'.
- #T1105: Ingress Tool Transfer by downloading payloads from Github.
- #T1496: Resource Hijacking with #XMRig. -
From a #ThreatIntelligence perspective, the #TTPs would be:
- #T1059.003: Command and Scripting Interpreter: Unix Shell. SHC payloads to be run still need a shell to be identified in the system and that the code inside the payload is, in fact, a shell script.
- #T1027.002: Obfuscated Files or Information: Software Packed with #SHC.
- #T1622: Debugger Evasion by using SHC with '-r'.
- #T1105: Ingress Tool Transfer by downloading payloads from Github.
- #T1496: Resource Hijacking with #XMRig. -
Yesterday CISA and the FBI published a joint advisory on an Iranian #APT compromising FCEB (Federal Civilian Executive Branch) systems. The threat actors exploited #Log4Shell in an unpatched VMware Horizon server, installed #XMRig crypto mining software, moved laterally to the DC, compromised credentials with #Mimikatz, and then backdoored with #Ngrok on several hosts to maintain persistence.
My question is, why the hell they would go out of their way to install XMRig as part of this attack? Was it,
- for Lulz?
- to obfuscate their intent?
- financial motive?
From what I know, "for the Lulz" really isn't part of the APT playbook, and the only APT with financial motive that I'm ware of is North Korea, where cybercrime is literally part of their GNI (Gross National Income). My guess is to obfuscate, but I'd love to hear other people's thoughts on this.
-
Yesterday CISA and the FBI published a joint advisory on an Iranian #APT compromising FCEB (Federal Civilian Executive Branch) systems. The threat actors exploited #Log4Shell in an unpatched VMware Horizon server, installed #XMRig crypto mining software, moved laterally to the DC, compromised credentials with #Mimikatz, and then backdoored with #Ngrok on several hosts to maintain persistence.
My question is, why the hell they would go out of their way to install XMRig as part of this attack? Was it,
- for Lulz?
- to obfuscate their intent?
- financial motive?
From what I know, "for the Lulz" really isn't part of the APT playbook, and the only APT with financial motive that I'm ware of is North Korea, where cybercrime is literally part of their GNI (Gross National Income). My guess is to obfuscate, but I'd love to hear other people's thoughts on this.
-
#CISA released an Alert today regarding Iranian Government-Sponsored APT actors
+ exploiting #Log4Shell
+ dropping #XMRig crypto miner
+ leveraging #Ngrok for persistence
#threatintel #infosec -
#CISA released an Alert today regarding Iranian Government-Sponsored APT actors
+ exploiting #Log4Shell
+ dropping #XMRig crypto miner
+ leveraging #Ngrok for persistence
#threatintel #infosec