Cryptohacking: crypto-malware prevents remote code execution attacks

Words
739
Reading
4 min
Listen
Play
8y

Researchers at the Imperva cyber security company say they found the source of 90 percent of the remote code execution attacks in December 2017: cyber-malware.


Source

In a publication dated February 20, 2018, Imperva evaluates the recent increase in attacks of this type of threat. They specifically examine the amount of money that the outright attackers are taking, while providing risk management advice to organizations that try to stay out of them.

Here are some of the key findings :

Criptominer malware causes the denial of service to the infected server. When most of the computing power of the server is directed to coin mining it may not respond to requests for its own functions.

The elimination of malware is not simple due to its persistent nature, since it adds tasks scheduled to be downloaded and executes them again after a certain period of time.

Although, as they say, Bitcoin is the most popular cryptocurrency that exists, there is no evidence that a single attack has occurred through the use of cryptocurrency mining software.

Other crypts, such as Monero, are at greater risk, because they are newer and can be extracted using a common CPU. Hence, Monero has become the preferred choice of hackers to run a server infection.

In the downloaded configuration files that Imperva identified, there were active Monero purses that belonged to the attackers. By tracking the portfolios and mining groups, Imperva could see the amount of money obtained by the cryptohackers, an estimated 41 moneros or around US $ 10,000. Imperva could also see that they were earning around 1.5 moneros a day, approximately US $ 375.

Electroneum , a relatively new cryptocurrency based in the United Kingdom, published specifically for users of mobile devices in September 2017, has also been subject to attacks. The revision of Imperva yielded the following results: The hackers had mined more than 220,000 Electroneum, valued at around US $ 15,500 by then.

Another cryptocurrency hit was Karbowanec , from Ukraine, or Karbo, for short. A Karbo wallet found in Imperva's data had been emptied of around 275 Karbos, which at the time were worth $ 379.

Varun Badhwar, security expert, CEO and co-founder of the cloud threat defense company RedLock , said in a statement sent by email to Bitcoin Magazine that the rising value of cryptocurrencies has captured the attention of the public around the world. , including hackers. He believes that it is increasingly lucrative for them to steal the computing power to extract cryptocurrencies that steal data.

Badhwar also points out that we are seeing cryptojacking attacks in organizations to take advantage of the computing power within their networks. This is a much stealthier tactic since the activity often goes unnoticed in large organizations where there are remnant or underutilized computing resources.

He cites a series of crypto-incidents that the RedLock research team has already discovered in AWS and Azure environments belonging to large multinational organizations such as Gemalto and Aviva.


Source

In his opinion, all this is just the tip of the iceberg, and he believes that this type of cybercrime will increase in scale and speed in the near future.

"The main attack vector for these attacks are committed credentials that are used to infiltrate environments, activate compute instances, and perform mining operations.As a result, organizations must institute strict user access policies and closely monitor their activities to detect anomalous behavior, "says Badhwar.

Nick Bilogorskiy, cybersecurity strategist at Juniper Networks, added in an email response to BM: "The history with mining and cryptojacking malware is really about Monero and Electroneum. The difficulty of Bitcoin mining is already too high and can not be exploited effectively in CPUs, only in special purpose hardware. "

Bilogorskiy says that the price of these crypts has more than doubled in recent months, which makes extraction even more profitable. It also helps, he says, that Monero, like Dash and ZCash, are private currencies, which makes them virtually impossible to trace and "safe" for criminals.

And he continues: "Crypto-domain malware allows attackers to monetize the power of compromised computers. Cryptojacking allows them to reach an even greater scale by taking over the browsers of website visitors. "

"Increasingly, the power and processing power of the CPU is becoming the new currency of the dark side of the Internet. These new crypto-attacks are like leeches, absorb the energy of our homes and businesses, block computers and melt the batteries of our phones, "he said.

Cryptohacking: crypto-malware prevents remote code execution attack... | Ecency