Another attack by hidden Monero miners on Android and Apple devices

Another attack by hidden Monero miners on Android and Apple devices

A team of Chinese cybersecurity researchers 360 Netlab reports the emergence of new versions of malware aimed at hidden mining of the Monero cryptocurrency

Just as often as we hear about regulation and restrictions, we now hear about hacks and malware. New hackerware is discovered almost every week as cybercriminals move from extortion to developing malware aimed at the cryptocurrency market. Thus, Chinese security researchers recently discovered an Android-based mining worm.

According to the Chinese cybersecurity company 360 Netlab, a hidden mining malware called ADB was discovered. As in previous cases, the virus uses the device’s hardware and makes it part of the Monero cryptocurrency mining network.

The hacker software uses open debug ports 5555 on a smartphone, tablet or set-top box to inject itself. A diagnostic debugging tool may unintentionally leave this port open, which is what the ADB-activating virus takes advantage of and spreads to other Android devices. 

Researchers have discovered that the malware contains Mirai botner code. Last year, Mirai infected millions of IoT devices to launch waves of DDoS attacks. A modified version of Mirai called Satori also works as a hidden Ethereum mining through port 3333.

Hackers have not bypassed Apple. According to security company Sentinel One, a new Mac malware has been discovered that is being distributed via MacUpdate. The Mac Trojan, called OSX, also uses CPU power to mine Monero undetected by the user. По словам исследователей безопасности, MalwarebytesLab:

«Вирусная программа была распространена посредствам взлома сайта MacUpdate и внедрение ее в копии приложений Firefox, OnyX и Deeper. This is the third variant of the virus program discovered this year.”

Such incidents are gaining momentum as cryptocurrencies become more attractive to cybercriminals. Just this year, malware was found in YouTube and Google ads, and Facebook's Messenger was previously attacked. 



Subscribe to our news in Telegram

According to bitcoinist

You May Also Like

182018-06-26

Cryptocurrency exchanges are attacked through Hangul Word Processor documents

According to cybersecurity company AlienVault, the author of the infected HWP documents used in recent attacks on exchanges is the North Korean government-funded group Lazarus.

Security
352018-09-27

The Good, the Bad and the Ugly Bitcoin Bug

For over a year, all versions of Bitcoin Core contained one of the worst bugs in Bitcoin history. In this article, we will reveal the good, bad and ugly details about one of the most annoying Bitcoin Core bugs to date.

Bitcoin, Security

Latest articles from Security category

Fresh video on our Channel