Security News

Crackonosh virus mined $2 million of Monero from 222,000 hacked computers
2021-06-27 20:00

A previously undocumented Windows malware has infected over 222,000 systems worldwide since at least June 2018, yielding its developer no less than 9,000 Moneros in illegal profits. Dubbed "Crackonosh," the malware is distributed via illegal, cracked copies of popular software, only to disable antivirus programs installed in the machine and install a coin miner package called XMRig for stealthily exploiting the infected host's resources to mine Monero.

Monero-mining botnet targets orgs through recent MS Exchange vulnerabilities
2021-04-22 10:49

The recent Microsoft Exchange Server vulnerabilities might have initially been exploited by a government-backed APT group, but cybercriminals soon followed suit, using them to deliver ransomware and grow their botnet. One perpetrator of the latter activities is Prometei, a cross-platform, modular Monero-mining botnet that seems to have flown under the radar for years.

New Malware Hijacks Kubernetes Clusters to Mine Monero
2021-02-03 20:50

Researchers have discovered never-before-seen malware, dubbed Hildegard, that is being used by the TeamTNT threat group to target Kubernetes clusters. Eventually, they warn, TeamTNT may launch a more large-scale cryptojacking attack via Kubernetes environments or steal data from applications running in Kubernetes clusters.

New worm turns Windows, Linux servers into Monero miners
2020-12-30 09:40

A newly discovered and self-spreading Golang-based malware has been actively dropping XMRig cryptocurrency miners on Windows and Linux servers since early December. The C2 server is used to host the bash or PowerShell dropper script, a Golang-based binary worm, and the XMRig miner deployed to surreptitiously mine for untraceable Monero cryptocurrency on infected devices.

PGMiner, Innovative Monero-Mining Botnet, Surprises Researchers
2020-12-11 19:41

An innovative Linux-based cryptocurrency mining botnet has been uncovered, which exploits a disputed PostgreSQL remote code-execution vulnerability to compromise database servers. The miner takes a fileless approach, deleting the PostgreSQL table right after code launch, researchers said: PGMiner clears the "Abroxu" table if it exists, creates a new "Abroxu" table with a text column, saves the malicious payload to it, executes the payload on the PostgreSQL server and then clears the created table.

Blue Mockingbird Monero-Mining Campaign Exploits Web Apps
2020-05-07 21:01

A Monero cryptocurrency-mining campaign has emerged that exploits a known vulnerability in public-facing web applications built on the ASP.NET open-source web framework. The campaign has been dubbed Blue Mockingbird by the analysts at Red Canary that discovered the activity.

T-Mobile US hacked, Monero wallet app infected, public info records on 1.2bn people leak from database...
2019-11-23 10:06

...OnePlus also compromised, and much more Roundup Time for another roundup of all the security news that's fit to print and that we haven't covered yet.…

Official Monero site delivers malicious cash-grabbing wallet
2019-11-21 12:18

If you downloaded the Monero command line wallet recently, check it before using it.

Monero Project site compromised, served malware-infected binaries
2019-11-20 10:25

The official website of the Monero Project has been compromised to serve a malware-infected version of the CLI (command-line interface) wallet. The malicious file was available for download for...

Cryptocurrency Stealer Delivered From Official Monero Website
2019-11-20 09:35

The official website for the Monero cryptocurrency was hacked recently and attackers replaced legitimate wallet files offered for download with a malicious version. read more