Executive Summary

The Fortra Intelligence and Research (FIRE) team has discovered and aided in the mitigation of a malware campaign delivering an open-source cryptocurrency miner, known as XMRig. This campaign stands out to security researchers because cryptojacking or malicious cryptocurrency mining operations rarely target enterprise environments with these methods, and more frequently focus on individuals due to the larger pool of available targets, lower security practices, and smaller risk of detection.

The actors behind these attacks used uncommon staging methods and a rarely seen persistence technique, prompting a deeper technical analysis to determine the real purpose and potential impact to enterprise environments. The targets were mainly larger financial groups, banking institutions, and wealth management firms.

The method of delivery is the typical phishing email, in this instance containing a link to a Czech-based online file-sharing and storage service urging the recipient to download a backup of their cryptocurrency wallet. After downloading, unzipping, and running the malicious payload, the malware will reach out to the threat actor’s infrastructure for more instructions. Using many observed evasion and anti-analysis techniques, its goal is to persist on the infected system as long as possible, use system resources without consent, and send back as much cryptocurrency as possible to the wallet specified by the attacker.

Cryptocurrency Miners and XMRig

Cryptocurrency miners are software programs designed to utilize system resources, such as the processor, to generate virtual currency. This software will continuously utilize these resources requiring a constant source of power. The goal of an attacker using a cryptocurrency miner is to infect as many systems as possible for as long as possible, maximizing profit from mined cryptocurrency.

Once a system is compromised via a cryptocurrency miner, the attacker can send further instructions to the malware and perform reconnaissance, or they can deploy other malware capable of stealing information, granting remote access, or more.

XMRig is an open-source cryptocurrency miner primarily developed for mining Monero, although it supports other types of coin. Written in C and C++ the source code of this coin miner is available to the public. It is a legitimate piece of software that threat actors unfortunately abuse.

Their own documentation highlights its capabilities to use both CPU and GPU resources for mining. There are versions available for Windows, Linux, and MacOS.

Breakdown

Staging

Throughout this campaign, there were two main staging methods observed. The first involves a zip file which contains an executable. The second and more interesting infection chain begins with the delivery of a .reg file – a method that is uncommon. This is perhaps because Windows will notify the user that this file type can damage the system or because larger organizations with better security practices block these files from running or from ever reaching the user.

When a .reg file is opened it can set up something called a registry key on Windows machines. Registry keys are generally small files containing information read by the Windows operating system to determine its own configuration or behavior. Anything from the profile picture of the user’s account to the software that is loaded at start up is stored in these registry keys. This is what our malware sample is abusing.

Read the full article here

_______

If this information is helpful to you, read our blog for more interesting and useful content, tips, and guidelines on similar topics. Contact the team of COMPUTER 2000 Bulgaria now if you have a specific question. Our specialists will be assisting you with your query. 

Content curated by the team of COMPUTER 2000 on the basis of news in reputable media and marketing materials provided by our partners, companies, and other vendors.

 

 

Follow us to learn more

CONTACT US

Let’s walk through the journey of digital transformation together.

By clicking on the SEND button you agree to the processing of personal data. In accordance with our Privacy Policy

15 + 10 =