Security News

Fake Ad Blocker Delivers Hybrid Cryptominer/Ransomware Infection
2021-03-10 21:44

At its previous peak in February, the Monero Miner cryptocurrency ransominer was targeting more than 2,500 users a day, disguised as an antivirus installer. Now, the tricky hybrid malware is on the rise again, this time impersonating an ad blocker and OpenDNS service.

Crypto-Miner Campaign Targets Unpatched QNAP NAS Devices
2021-03-08 21:16

UPDATE. Owners of popular QNAP Systems network attached storage devices are being warned that a malicious cryptocurrency campaign is actively exploiting two critical firmware bugs in systems that have not yet been patched. QNAP fixed the flaws in October 2020; however, researchers at Qihoo 360's Network Security Research Lab report a widening campaign targeting over 100 models used by 4.3 million of the company's NAS devices.

Nation-State Hackers Caught Hiding Espionage Activities Behind Crypto Miners
2020-12-01 00:54

A nation-state actor known for its cyber espionage campaigns since 2012 is now using coin miner techniques to stay under the radar and establish persistence on victim systems, according to new research. Attributing the shift to a threat actor tracked as Bismuth, Microsoft's Microsoft 365 Defender Threat Intelligence Team said the group deployed Monero coin miners in attacks that targeted both the private sector and government institutions in France and Vietnam between July and August earlier this year.

Kinsing Linux Malware Deploys Crypto-Miner in Container Environments
2020-04-06 13:12

A campaign that has been ongoing for months is targeting misconfigured open Docker Daemon API ports to install a piece of malware named Kinsing, which in turn deploys a cryptocurrency miner in compromised container environments. As part of the attack, hackers abuse misconfigured Docker API ports to run an Ubuntu container hosting Kinsing.

Vollgar Campaign Targets MS-SQL Servers With Backdoors, Crypto-Miners
2020-04-02 04:15

A recently uncovered attack campaign that stayed under the radar since May 2018 has targeted Microsoft SQL servers with backdoors and crypto-miners, Guardicore Labs reveals. Attacks begin with MS-SQL brute force login attempts and continue with a series of configuration changes to allow command execution.

'Panda' Group Makes Thousands of Dollars Using RATs, Crypto-Miners
2019-09-18 06:54

A new threat actor has generated thousands of dollars in the Monero cryptocurrency using remote access tools (RATs) and illicit cryptocurrency mining malware, Cisco’s Talos threat intelligence and...

Linux Crypto-Miner Uses Kernel-Mode Rootkits for Evasion
2019-09-17 15:13

A recently discovered cryptocurrency mining malware targeting Linux machines is employing kernel-mode rootkits in an attempt to make detection more difficult, Trend Micro reveals. read more

Firefox 69 Now Blocks 3rd-Party Tracking Cookies and Cryptominers By Default
2019-09-04 09:33

Mozilla has finally enabled the "Enhanced Tracking Protection" feature for all of its web browser users worldwide by default with the official launch of Firefox 69 for Windows, Mac, Linux, and...

Norman Cryptominer Employs Sophisticated Obfuscation Tactics
2019-08-14 13:24

A new XMRig Monero cryptominer stands apart, despite its non-flashy name.

Smominru Cryptominer Scrapes Credentials for Half-Million Machines
2019-08-07 14:51

The adversaries have retooled with EternalBlue and credential theft to add a new "access mining" revenue stream.