Security News > 2022 > June > New peer-to-peer botnet infects Linux servers with cryptominers

New peer-to-peer botnet infects Linux servers with cryptominers
2022-06-15 13:00

A new peer-to-peer botnet named Panchan appeared in the wild around March 2022, targeting Linux servers in the education sector to mine cryptocurrency.

At the same time, it has powerful detection avoidance capabilities, such as using memory-mapped miners and dynamically detecting process monitoring to stop the mining module immediately.

It infects new hosts by locating and using existing SSH keys or brute-forcing usernames and passwords.

The configurations sent to the malware concern either the miner configuration or updating the peer list.

Akamai modified the program to remove this security measure and found that the admin panel features a configuration overview, host status, peer stats, and miner settings, while it also gives operators updating options.

Panchan uses NiceHash for its mining pools and wallets, so Akamai's analysts couldn't trace transactions or estimate the size of the mining operation, profit, etc.


News URL

https://www.bleepingcomputer.com/news/security/new-peer-to-peer-botnet-infects-linux-servers-with-cryptominers/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Linux 11 64 2337 1502 67 3970