BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Malware Spreads As a Worm, Uses Cryptojacking Module to Mine for Monero

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading

A modular malware with worm capabilities exploits known vulnerabilities in servers running ElasticSearch, Hadoop, Redis, Spring, Weblogic, ThinkPHP, and SqlServer to spread from one server to another and mine for Monero cryptocurrency.

Systemctl.exe, the worm module of the malware named PsMiner by the 360 Total Security researchers, is a Windows binary written in the Go language which bundles all the exploit modules used to hack into vulnerable servers it can find on the Internet.

Besides the exploits, PsMiner’s worm module also has the capability to brute force its way in, whenever it finds targets that uses weak or default credentials, as well as crack user credentials using an additional brute force password cracking component.

- Advertisement -

Once it manages to infiltrate a victim’s computer, PsMiner will execute a PowerShell command which downloads a WindowsUpdate.ps1 malicious payload, the malware’s master module designed to drop the Monero miner as part of the final infection stage.

The infection process
The infection process

The malware will also copy the malicious WindowsUpdate.ps1 script to the Windows Temp folder and will create an “Update service for Windows Service” scheduled task designed to re-launch the main malware module every 10 minutes to help it keep persistence on the compromised system.

During the last stage of the infection, PsMiner will download and launch the open source Xmrig CPU miner, used to mine for Monero cryptocurrency with the help of a custom mining profile.

While the worm capabilities it uses to spread between its victims and the way it uses living-off-the-land (LotL) techniques to further compromise its targets and achieve persistence are quite effective, not the same thing can be said about the profits this campaign was able to collect for its masters.

As the 360 Total Security researchers say in their report, “Inquiring about the relevant transaction records, we found that in just two weeks, the miner accumulated a total of about 0.88 Monroe (sic) coins.”

Malware modules
Malware modules

Cryptojacking still a threat

According to Symantec’s 2019 Internet Security Threat Report, the use of malicious PowerShell scripts increased by a whopping 1,000% during 2019, closely following the overall trend of cybercriminals moving to LotL techniques to avoid being detected while infiltrating their targets’ systems.

Even though the use of cryptojacking malware followed a downward trend during 2018, it’s still in the arsenal of threat actors as shown by PsMiner, by a batch of eight Microsoft Store apps found to be dropping malicious Monero cryptomining scripts, and by hundreds of vulnerable and exposed Docker hosts actively being abused in cryptojacking campaigns.

Additionally, a new Backdoor Trojan dubbed SpeakUp which drops XMRig miners on its victims and a new coinminer malware strain using the XMR-Stak Cryptonight cryptocurrency miner were detected targeting servers multiple Linux distributions.

Cryptocurrency mining malware also affected ten times more organizations than ransomware did during last year, while and more and more malware families have begun to merge in new capabilities targeting cryptocurrency within their arsenal, as detailed by a Check Point Research report.

Previous Articles:

- Advertisement -
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Gold Crashes to 4-Month Low; Strategists Keep $5K–$6.3K Targets

Gold crashed to a four-month low of $4,098, posting its worst five-session performance since...

Baltimore sues xAI over Grok’s millions of non-consensual deepfakes

The Mayor and City Council of Baltimore have sued X Corp., xAI, and SpaceX,...

SpaceX Targets Historic $75B IPO Filing This Week

SpaceX may file for its record-breaking IPO as soon as this week, targeting a...

Ethereum Aims for Quantum Resistance by 2029

The Ethereum Foundation has launched a "Post-Quantum Ethereum" resource hub to address future quantum...

NASA Shifts Artemis to Build $20B Permanent Moon Base

NASA has shifted its Artemis program strategy, now prioritizing the construction of a permanent...

Must Read

TOP 12 Day Trading Crypto Books For Beginners

Day trading cryptocurrencies has become an increasingly popular financial activity, offering the potential for huge returns to those who understand the market's complexities and...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading