Researchers Say KingMiner Malware Is Evolving

- Advertisement -

November 30, 2018 11:01 PM

The malware can delete old versions of itself to evade detection.

Two researchers from Israel-based Check Point Software Technologies Ltd. have revealed that a type of crypto mining malware is “evolving” to avoid detection, according to research notes published on November 29.

The research done by Ido Solomon and Adi Ikan centered around a type of crypto mining malware called KingMiner. As per the research notes, KingMiner emerged in June 2018, and specifically targets Microsoft servers, usually seeking out servers using “IIS or SQL,” to mine Monero tokens.

- Advertisement -

According to Solomon and Ikan, “The attacker employs various evasion techniques to bypass emulation and detection methods, and, as a result, several detection engines have noted significantly reduced detection rates.”

Once KingMiner infects a server, it tries to guess the password. When the password is obtained, the malware then downloads and executes a Windows scriptlet file. In order to avoid detection, KingMiner searches for and deletes older versions of itself, then replaces them with new versions that can bypass code emulation, which is a method for detecting malware.

Solomon and Ikan found that the attacker uses three other features to avoid monitoring and detection: a private mining pool with the application programming interface turned off, a wallet not used in public mining pools, and private domains. This drastically reduces the rate at which anti-malware software can detect and remove KingMiner from infected servers.

KingMiner malware has infected servers globally, including in Mexico, India, Norway, and Israel.

Solomon and Ikan conclude their research with a warning:

“KingMiner is an example of evolving Crypto-Mining malware that can bypass common detection and emulation systems. By implementing simple evasion techniques, the attacker can increase the probability of a successful attack. We predict that such evasion techniques will continue to evolve during 2019 and become a major (and more common) component in Crypto-Mining attacks.”

With the proliferation of cryptocurrency, mining malware has become commonplace. In July 2017, ETHNews reported that servers at San Francisco State University had been infected with bitcoin-mining malware. In February of this year, we reported that more than 4,000 websites – including government-run sites – in the US and the UK were hijacked by crypto mining malware. And, just Wednesday, November 28, Kaspersky Lab issued a report warning of the dangers of new crypto-mining malware.

Nathan Graham is a full-time staff writer for ETHNews. He lives in Sparks, Nevada, with his wife, Beth, and dog, Kyia. Nathan has a passion for new technology, grant writing, and short stories. He spends his time rafting the American River, playing video games, and writing.

Like what you read? Follow us on X @Bitnewsbot to receive the latest KingMiner, malware or other Ethereum technology news.



Previous Articles:

- Advertisement -

Latest News

Machado emerges as bitcoin-friendly frontrunner in Venezuela

Nicolás Maduro was captured Saturday and transferred to New York to face federal charges,...

Crypto Fear and Greed Index Flips to Neutral; BTC Steady now

CoinMarketCap’s Fear and Greed Index moved to “neutral” at 40 on Sunday, indicating improved...

Altcoin market poised to retest $1.2T high, analyst says now

The altcoin market capitalization sits above $879 billion and is positioned for a potential...

Will ETF Inflows Push XRP to $10 in 2026? Analysts Weigh In.

Summarize the article from Ripple’s XRP token had one of its best years in...

Weak yen gives Metaplanet edge among Bitcoin treasuries now!

Metaplanet may gain a financing advantage from a structurally weak Japanese yen, according to...
- Advertisement -

Must Read

Top 5 Best Crypto Faucets To Earn Free Crypto This Year

QUICK LINKSWhat Are Crypto Faucets and How Do They Work?How Do Crypto Faucets Make Money?What to Expect: Realistic EarningsThe Best Crypto Faucets of 2025:...
Bitcoin (BTC) $ 92,934.00 1.98%
Ethereum (ETH) $ 3,194.14 1.58%
XRP (XRP) $ 2.15 5.68%
Bittensor (TAO) $ 268.80 4.80%
Polkadot (DOT) $ 2.15 1.29%
Cardano (ADA) $ 0.404664 2.74%
Chainlink (LINK) $ 13.72 2.94%
Hyperliquid (HYPE) $ 26.76 6.05%
Monero (XMR) $ 424.25 2.39%
Hedera (HBAR) $ 0.128425 5.79%
Toncoin (TON) $ 1.88 0.65%