New Crypto-Miner Attacks Linux Machines, Kills Other Miners and Anti-Malware
#1
Quote:The Russian Dr.Web anti-malware maker discovered a new Linux threat embodied by a Trojan designed to work as a crypto-miner and as a dropper for some other nasty malware payloads such as DDoS backdoors and rootkits.

The new Trojan strain named Linux.BtcMine.174 by the Dr.Web team is a heavy 1,000-line shell script which comes with multiple modules that it will download and write to any folder with write permissions on the infiltrated Linux box.

Once it has managed to dump the extra malware payloads on the compromised machine, Linux.BtcMine.174 will use the nohup POSIX utility to launch itself as a daemon, redirecting its output to a nohup.out file to make detection more difficult.

After installing itself as a service, the Trojan downloads a Linux.BackDoor.Gates.9 Trojan payload that makes it possible for its masters to control the compromised machine and use it to execute DDoS attacks.

Because after compromising its Linux targets the Trojan is running under the privileges of the current user, almost never an administrator account, Linux.BtcMine.174 uses exploits such as Linux.Exploit.CVE-2016-5195 (known as DirtyCow) and Linux.Exploit.CVE-2013-2094 to escalate its privileges and completely take over the Linux machine.

Source: https://news.softpedia.com/news/new-cryp...3958.shtml
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
AxCrypt 3.0.0.94
AxCrypt 3.0.0.94: ...harlan4096 — 11:41
NVIDIA GeForce Game Ready 596.49 driver
Highlights  Gam...harlan4096 — 11:40
AMD launches six new Ryzen PRO 9000 CPUs...
AMD Ryzen PRO 9000...harlan4096 — 11:39
AMD HDMI 2.1 DSC patches could bring 4K ...
AMDGPU HDMI 2.1 pa...harlan4096 — 11:37
Vulkan 1.4.351 adds six extensions with ...
Khronos releases V...harlan4096 — 11:35

[-]
Birthdays
Today's Birthdays
avatar (38)owysykan
avatar (49)beautgok
Upcoming Birthdays
avatar (28)akiratoriyama
avatar (48)Jerrycix
avatar (40)awedoli
avatar (82)WinRARHowTo
avatar (39)axuben
avatar (40)ihijudu
avatar (45)tiojusop
avatar (42)Damiennug
avatar (40)acoraxe
avatar (49)contjrat
avatar (44)knigiJow
avatar (46)1stOnecal
avatar (50)Mirzojap
avatar (36)idilysaju
avatar (40)GregoryRog
avatar (45)mediumog
avatar (40)odukoromu
avatar (46)Joanna4589

[-]
Online Staff
harlan4096's profile harlan4096
Administrator
mjcn19's profile mjcn19

>