• Latest
Cybercriminals Use Obfuscation Trick to Install Crypto Mining Malware

Cybercriminals Use Obfuscation Trick to Install Crypto Mining Malware

Juni 28, 2019
6 Questions for Rene Reinsberg of Celo – Cointelegraph Magazine

6 Questions for Rene Reinsberg of Celo – Cointelegraph Magazine

März 31, 2023
Judge denies SEC motion to keep Hinman docs secret in Ripple case

Judge denies SEC motion to keep Hinman docs secret in Ripple case

März 31, 2023
The ultimate guide to Miami – Cointelegraph Magazine

The ultimate guide to Miami – Cointelegraph Magazine

März 31, 2023
Dr. Jane Thomason – Cointelegraph Magazine

Dr. Jane Thomason – Cointelegraph Magazine

März 31, 2023
1658007797 celsius is bankrupt with 12b balance sheet hole su zhu.jpg

Celsius is bankrupt with $1.2B balance sheet hole, Su Zhu returns to Twitter and OpenSea purges 20% of employees: Hodler’s Digest, July 10-16

März 31, 2023
6 Questions for Lisa Fridman of Quadrata – Cointelegraph Magazine

6 Questions for Lisa Fridman of Quadrata – Cointelegraph Magazine

März 31, 2023
Jed McCaleb empties XRP wallet after eight-year selloff

Jed McCaleb empties XRP wallet after eight-year selloff

März 31, 2023
Celsius has finally filed for bankruptcy: Law Decoded, July 18-25

Celsius has finally filed for bankruptcy: Law Decoded, July 18-25

März 31, 2023
The ‘godfather of crypto’ risked lifetime in jail, laying foundation for Bitcoin – Cointelegraph Magazine

The ‘godfather of crypto’ risked lifetime in jail, laying foundation for Bitcoin – Cointelegraph Magazine

März 31, 2023
SEC objects to XRP holders aiding Ripple defense

SEC objects to XRP holders aiding Ripple defense

März 31, 2023
Blockchain technology is transforming the real estate market – Cointelegraph Magazine

Blockchain technology is transforming the real estate market – Cointelegraph Magazine

März 31, 2023
1658612147 nfts banned in minecraft sec lists 9 tokens as securities.jpg

NFTs banned in Minecraft, SEC lists 9 tokens as securities and 3AC founder blames cockyness for company meltdown: Hodler’s Digest, July 17-23

März 31, 2023
  • Home
  • Coin Market Cap
  • Bitcoin
  • Ethereum
  • Ripple
  • Litecoin
  • Alt Coin
  • Business
  • Trading
  • Mining
CoinNewsDaily
  • Home
  • Coin Market Cap
  • Bitcoin
  • Ethereum
  • Ripple
  • Litecoin
  • Alt Coin
  • Business
  • Trading
  • Mining
No Result
View All Result
  • Home
  • Coin Market Cap
  • Bitcoin
  • Ethereum
  • Ripple
  • Litecoin
  • Alt Coin
  • Business
  • Trading
  • Mining
No Result
View All Result
CoinNewsDaily
No Result
View All Result
Home Litecoin

Cybercriminals Use Obfuscation Trick to Install Crypto Mining Malware

coinnewsdaily by coinnewsdaily
Juni 28, 2019
in Litecoin
0
Cybercriminals Use Obfuscation Trick to Install Crypto Mining Malware
190
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

Cybersecurity firm Trend Micro has confirmed that attackers have been exploiting a vulnerability in the Oracle WebLogic server to install monero (XMR) mining malware, while using certificate files as an obfuscation trick. The news was revealed in a Trend Micro blog post published on June 10.

As previously reported, forms of stealth crypto mining are also referred to with the industry term cryptojacking — the practice of installing malware that uses a computer’s processing power to mine for cryptocurrencies without the owner’s consent or knowledge.

Related articles

Litecoin confidential transactions spook Korean exchanges

Litecoin confidential transactions spook Korean exchanges

Mai 23, 2022
Do Kwon faces legal trouble in South Korea, China remains Bitcoin mining powerhouse, and Ethereum 2.0 eyes ‘huge testing milestone’: Hodler’s Digest, May 15-21

Do Kwon faces legal trouble in South Korea, China remains Bitcoin mining powerhouse, and Ethereum 2.0 eyes ‘huge testing milestone’: Hodler’s Digest, May 15-21

Mai 22, 2022

According to Trend Micro’s post, a security patch for theOracle WebLogic vulnerability (“CVE-2019-2725”) — reportedly caused by a deserialization error — was released in the national vulnerability database earlier this spring.

However, Trend Micro cites reports that emerged on the SANS ISC InfoSec forum alleging that the vulnerability has already been exploited for cryptojacking purposes, and confirms that it has verified and analyzed the allegations.

The firm notes that the identified attacks deployed what it describes as “an interesting twist” — namely that “the malware hides its malicious codes in certificate files as an obfuscation tactic”:

“The idea of using certificate files to hide malware is not a new one […] By using certificate files for obfuscation purposes, a piece of malware can possibly evade detection since the downloaded file is in a certificate file format which is seen as normal -— especially when establishing HTTPS connections.”

Trend Micro’s analysis begins by noting that the malware exploits CVE-2019-2725 to execute a PowerShell command, prompting the download of a certificate file from the command-and-control server.

After continuing to trace its steps and characteristics — including the installation of the XMR miner payload — Micro Trend notes an apparent anomaly in its current deployment:

“[O]ddly enough, upon execution of the PS command from the decoded certificate file, other malicious files are downloaded without being hidden via the certificate file format mentioned earlier. This might indicate that the obfuscation method is currently being tested for its effectiveness, with its expansion to other malware variants pegged at a later date.”

The post concludes with a recommendation to firms using WebLogic Server to update their software to the latest version with the security patch in order to mitigate the risk of cryptojacking.

As recently reported, Trend Micro detected a major uptick in XMR cryptojacking targeting China-based systems this spring, in a campaign mimicking earlier activities that had used an obfuscated PowerShell script to deliver XMR-mining malware.



Credit: Source link

Tags: Litecoin
Share76Tweet48
Previous Post

Overstock’s tZero Launches Mobile Crypto App Touted as Hack-Resistant

Next Post

27% of UK Residents Want to See Crypto in More Real-World Applications

coinnewsdaily

coinnewsdaily

CoinNewsDaily.com is an online Crypto Coin News Website that aims to provide latest trendy news from market and around the world.

Related Posts

Litecoin confidential transactions spook Korean exchanges
Litecoin

Litecoin confidential transactions spook Korean exchanges

Mai 23, 2022
Do Kwon faces legal trouble in South Korea, China remains Bitcoin mining powerhouse, and Ethereum 2.0 eyes ‘huge testing milestone’: Hodler’s Digest, May 15-21
Litecoin

Do Kwon faces legal trouble in South Korea, China remains Bitcoin mining powerhouse, and Ethereum 2.0 eyes ‘huge testing milestone’: Hodler’s Digest, May 15-21

Mai 22, 2022
Terra ecosystem collapses, Sam Bankman-Fried buys Robinhood stock and crypto trader receives jail sentence for Ponzi scheme: Hodler’s Digest, May 8-14
Litecoin

Terra ecosystem collapses, Sam Bankman-Fried buys Robinhood stock and crypto trader receives jail sentence for Ponzi scheme: Hodler’s Digest, May 8-14

Mai 19, 2022
meta to launch metaverse hardware store, elon musk buys twitter for $44b and apecoin pumps to new highs: hodler’s digest, april 24 30
Litecoin

Meta to launch metaverse hardware store, Elon Musk buys Twitter for $44B and ApeCoin pumps to new highs: Hodler’s Digest, April 24-30

Mai 5, 2022
Bitcoin Will Overtake Gold’s MarketCap in 9 years, Says Bobby Lee |
Bitcoin

Sell or hodl? How to prepare for the end of the bull run, Part 2

April 10, 2022
How to prepare for the end of the bull run, Part 1: Timing
Bitcoin

How to prepare for the end of the bull run, Part 1: Timing

April 3, 2022
Load More
Next Post
27% of UK Residents Want to See Crypto in More Real-World Applications

27% of UK Residents Want to See Crypto in More Real-World Applications

Kategorien

  • Alt Coin
  • Bitcoin
  • Business
  • Ethereum
  • ICO
  • Litecoin
  • Mining
  • NFT
  • Ripple
  • Tech
  • Trading

What New here?

  • 6 Questions for Rene Reinsberg of Celo – Cointelegraph Magazine
  • Judge denies SEC motion to keep Hinman docs secret in Ripple case
  • The ultimate guide to Miami – Cointelegraph Magazine
  • About Us
  • Contact Us
  • Privacy & Policy

© 2018-2021 CoinNewsDaily.com by CoinNewsDaily Inc. Crafted with Love by iFtiDev

Please enter CoinMarketCap Free Api Key to get this plugin works.
✕
No Result
View All Result
  • Home
  • Coin Market Cap
  • Bitcoin
  • Ethereum
  • Ripple
  • Litecoin
  • Alt Coin
  • Business
  • Trading
  • Mining

© 2018-2021 CoinNewsDaily.com by CoinNewsDaily Inc. Crafted with Love by iFtiDev