Windows and Linux servers turned into crypto miners

Lock
(Image credit: Shutterstock)

Security researchers have discovered a new malware that installs a legitimate cryptocurrency mining program on poorly secured Windows and Linux servers. 

Intezer’s Avigayil Mechtinger, who specializes in malware analysis, has been tracking the multi-platform worm that installs XMRig Miner to mine the Monero cryptocurrency since early December.  

According to Mechtinger, the worm targets public facing MySQL, Tomcat, and Jenkins installations that have weak passwords.

Active and mutating

Explaining the workflow of the worm, Mechtinger writes that the worm scans for Tomcat, Jenkins, and MySQL services with open ports and then brute-forces its way inside. It then delivers a loader script on the compromised server that’ll drop and run the XMRig Miner. 

An earlier version of the worm also attempted to exploit the latest vulnerability in WebLogic (CVE-2020-14882). During Mechtinger’s analysis, the attacker kept updating the worm on the Command and Control (C&C) server. This indicates “that it’s active and might be targeting additional weak configured services in future updates,” she writes.

screenshot of Intezer's Analysis

(Image credit: Intezer)

In her report, Mechtinger notes that the worm’s code is “nearly identical” for both Windows and Linux targets, which to her “demonstrates that Linux threats are still flying under the radar for most security and detection platforms.”

Note that this latest worm follows the discovery of the PgMiner worm, which exploited a disputed vulnerability in PostgreSQL servers running on Linux to install a cryptocurrency miner. 

Mechtinger also makes note of another trend: “In 2020, we saw a noticeable trend of Golang malware targeting different platforms, including Windows, Linux, Mac and Android. We assess with high confidence that this will continue in 2021.”

Via: BleepingComputer

TOPICS
Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Latest in Software & Services
woman listening to computer
AWS vs Azure: choosing the right platform to maximize your company's investment
A person at a desktop computer working on spreadsheet tables.
Trello vs Jira: which project management solution is best for you?
Autonomous finance
Quickbooks vs Quicken: what are the main strengths and weaknesses for your business
finance
Quickbooks vs Xero: which is the best for your business?
Group of people meeting
Zoom vs Google Meet: which is the best video conferencing tool for your business?
Fingers typing on a computer keyboard.
Microsoft 365 Personal vs Microsoft 365 Family: are there any real differences?
Latest in News
Stability AI 3D Video
Stability AI’s new virtual camera turns any image into a cool 3D video and I’m blown away by how good it is
The Google Wallet app with a mode for kids shown on-screen.
Google Wallet’s new kid-friendly payment system is a win for parents
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
A worrying Apple Password App vulnerability reportedlyleft users exposed for months
Google Pixel 9a
Google is delaying the Pixel 9a to fix a mystery “component quality issue”
The bottom left corner of an Android phone, showing the Phone, Messages, Google icons and Google Search bar
Google Messages remote delete will soon save you from texting embarrassment – and here's how it works
ExpressVPN mobile app and Aircove
ExpressVPN ‘reduces workforce’ for the second time in two years