News Malware Mines Monero On Cloud Servers

Malware Mines Monero On Cloud Servers


- Advertisment -

Researchers Xingyu Jin and Claud Xiao, of the cybersecurity firm Palo Alto Networks, published a report yesterday, January 17, regarding Monero mining malware from threat actor Rocke. The malware is said to disable cloud security software to avoid detection and mine Monero using exiting cloud servers.

According to the report, Rocke’s malware targets public cloud infrastructure running on Linux servers, specifically going after cloud security products by Chinese firms Tencent Cloud and Alibaba Cloud. After gaining access, the malware uses uninstall instructions available on Tencent and Alibaba’s websites and “some random blog posts on the Internet,” to remove the existing cloud security without exhibiting detectable vicious behavior.

The paper notes that early versions of Rocke’s malware only attempted to kill security and monitoring agents from Tencent. Because the malware’s authors developed more effective ways to avoid detection, the program can now uninstall the Tencent host security agent, the Tencent cloud monitor agent, the Alibaba threat detection service agent, the Alibaba CloudMonitor agent, and the Alibaba cloud assistant agent.

Once the cloud security and monitor products are uninstalled, the malware “begins to exhibit malicious behaviors.” Not only can the malware block other crypto mining malware from using the infected cloud server, it can also kill other crypto mining processes that may already exist. It can then trigger its “ultimate goal” of mining Monero from within the compromised Linux servers.

Jin and Xiao say that the Rocke group was originally discovered by Cisco’s Talos Intelligence Group in August 2018. Talos’ blog post calls Rocke the “Champion of Monero Miners” and outlines the malware’s most recent attack – at the time of the post – in July 2018.

Earlier this month, researchers Sergio Pastrana and Guillermo Suarez-Tangil, from Universidad Carlos III de Madrid and King’s College London, respectively, published their own report, estimating that hackers have mined at least 4.32 percent of the total Monero in circulation. The researchers assert that at least 2,218 active malicious mining campaigns have gathered roughly 720,000 XMR (worth $57 million), with a single campaign having mined more that 163,000 XMR, or about $18 million, at the time of the paper’s publishing.

According to Jin and Xiao, Palo Alto Networks has been in contact with Tencent Cloud and Alibaba Cloud to discuss the Rocke malware’s evasion techniques. “The variant of the malware used by the Rocke group,” they say, “is an example that demonstrates that the agent-based cloud security solution may not be enough to prevent evasive malware targeted at public cloud infrastructure.”

Nicholas Ruggieri studied English with an emphasis in creative writing at the University of Nevada, Reno. When he’s not quoting Vines at anyone who’s willing to listen, you’ll find him listening to too many podcasts, reading too many books, and crocheting too many sweaters for his dogs, RT and Peterman.

ETHNews is committed to its Editorial Policy

Like what you read? Follow us on Twitter @ETHNews_ to receive the latest Monero, malware or other Ethereum cryptocurrencies and tokens news.

Source link


Please enter your comment!
Please enter your name here

Latest news

Buy VPS With Bitcoin: The Top 10 List

In this article, we list the Best web hosting providers you can buy VPS with bitcoin. All...

5 of the Best Crypto Jobs Sites

The cryptocurrency and blockchain job market has exploded. With new blockchain start-ups and projects being founded at...

What’s the future of decentralized blockchains?

When Bitcoin was new and not valued at anything or just a few cents anyone could join...

My 5 favorite free crypto tools & sites I use daily

So I often get asked by friends, or people visiting my site about new tips for exciting...
- Advertisement -Malware Mines Monero On Cloud Servers

Cryptocurrency is The Last Kingdom Where You Can Keep Your Data Private

Data privacy has been a hot topic for quite some time now and particularly after the popularity...

How To Travel With Bitcoin: 9 Travel Companies Accepting Bitcoin

Bitcoin travel is a reality, as several travel companies now accept payments in cryptocurrencies for their services.

Must read

Buy VPS With Bitcoin: The Top 10 List

In this article, we list the Best...

5 of the Best Crypto Jobs Sites

The cryptocurrency and blockchain job market has...
- Advertisement -

You might also likeRELATED
Recommended to you