Crypto

Words
185
Reading
1 min
Listen
Play
8y

Mining Is The New Black: CryptoJacking Polyvalent Malware Via Email
Cryptojacking malware has so far tended to concentrate on one particular cryptocurrency, but that seems to be changing. Palo Alto Networks warns that it's observed a polyvalent cryptojacking attack that's equally capable of pilfering Bitcoin, Ethereum, Litecoin, and Monero. "ComboJack," as the miner is called, works against the user's clipboard. It takes advantage of users' propensity to copy and paste addresses rather than go through the trouble of retyping the each time they're needed. The malware looks for wallet addresses in the clipboard and replaces them with the address of the criminals' wallet. This technique has been used by the Evrial Trojan and CryptoShuffler malware. It's now being employed against a range of e-currencies. Most of the victims of ComboJack have so far been in the US and Japan. It's delivered through phishing. The malicious payload is carried in a PDF file attached to the email. That PDF contains an embedded rich text file that carries an exploit for CVE-2017-8579, a known vulnerability that had previously been used to deliver FinFisher spyware. See Security Week: https://www.securityweek.com/combojack-malware-steals-multiple-virtual-currencies

Crypto | Ecency