According to Kaspersky Lab researchers, cybercriminals have started using sophisticated infection methods and techniques borrowed from targeted attacks in order to install mining software on attacked PCs within organizations. The most successful group observed by Kaspersky Lab earned at least $7 million by exploiting their victims in just six months during 2017.

 

Although the cryptocurrency market is experiencing plenty of ups and downs, last year’s phenomena with surges in the value of Bitcoin has significantly changed not only global economics, but the world of cybersecurity as well. With the aim of earning cryptocurrency, criminals have started to use mining software in their attacks, which, like ransomware, has a simple monetization model.

 

But, unlike ransomware, it doesn’t destructively harm users and is able to stay undetected for a long time by silently using the PC’s power. Back in September 2017, Kaspersky Lab recorded a rise of miners that started actively spreading across the world, and predicted its further development. The latest research reveals that this growth has not only continued, but has also increased and extended.

 

Kaspersky Lab researchers recently identified a cybercriminal group with APT-techniques in their arsenal of tools to infect users with miners. They have been using the process-hollowing method that is usually used in malware and has been seen in some targeted attacks of APT actors, but has never been observed in mining attacks before.

 

The attack works in the following way: the victim is lured into downloading and installing an advertisement software with the miner installer hidden inside. This installer drops a legitimate Windows utility, with the main purpose being to download the miner itself from a remote server.

 

After its execution, a legitimate system process starts, and the legitimate code of this process is changed to malicious code. As a result, the miner operates under the guise of a legitimate task, so it will be impossible for a user to recognize if there is a mining infection.

 

It is also challenging for security solutions to detect this threat. In addition, miners mark this new process through the way it restricts any task cancellation. If the user tries to stop the process, the computer system will reboot. As a result, criminals protect their presence in the system for a longer and more productive time.

 

Based on Kaspersky Lab’s observations, the actors behind these attacks have been mining Electroneum coins and earned almost $7 million during the second half of 2017, which is comparable to the sums that ransomware creators used to earn.

 

We see that ransomware is fading into the background, instead giving way to miners. This is confirmed by our statistics, which show a steady growth of miners throughout the year, as well as by the fact that cybercriminals groups are actively developing their methods and have already started to use more sophisticated techniques to spread mining software. We have already seen such an evolution – ransomware hackers were using the same tricks when they were on the rise,” said Anton Ivanov, Lead Malware Analyst at Kaspersky Lab.

 

Overall, 2.7 million users were attacked by malicious miners in 2017, according to Kaspersky Lab data. That is approximately 50% higher than in 2016 (1.87 mln). They have been falling victims as a result of adware, cracked games and pirated software used by cybercriminals to secretly infect their PCs. Another approach used was web mining through a special code located in an infected web page. The most widely used web miner was CoinHive, discovered on many popular websites.

 

In order to stay protected, Kaspersky Lab recommends that users do the following:

  • Don’t click on unknown websites, or suspicious banners and ads;
  • Do not download and open unknown files from untrusted sources;
  • Install a reliable security solution such as Kaspersky Internet Security or Kaspersky Free that detects and protects you from all possible threats, including malicious mining software.

 

For organizations, Kaspersky Lab recommends the following:

 

More information on miners’ activities can be found on Securelist.com

 

Key trends in mining attacks and the latest discoveries of cryptocurrency threats will be presented at the Security Analyst Summit by Kaspersky Lab researchers, March 9 2018 : https://sas.kaspersky.com/


RECOMMENDED ARTICLE FOR TECHWORLD


 
DJI Introduces FlightHub Software to Help Enterprises Efficiently Manage Their Drone Operations
Techworld Date Posted: 8 November 2017 4:09 PM | 215 Views
DJI, the world’s leader in civilian drones and aerial imaging technology, unveiled FlightHub, a new software solution that helps enterprises and drone service providers efficiently manage their drone operations from a single platform.. See More
 
DJI Introduces FlightHub Software to Help Enterprises Efficiently Manage Their Drone Operations
Techworld Date Posted: 4:09 PM | 215 Views
DJI, the world’s leader in civilian drones and aerial imaging technology, unveiled FlightHub, a new software solution that helps enterprises and drone service providers efficiently manage their drone operations from a single platform.See More

 
Transcend® Offers a New Perspective with the DrivePro Body 60 Body Camera
Techworld Date Posted: 5 June 2018 10:44 AM | 257 Views
Transcend® Information, Inc. (Transcend®), a leading manufacturer of storage and multimedia products, proudly introduces the DrivePro Body 60 body camera. This state-of-the-art POV tethered camera is designed specifically for military and public safety professionals.... See More
 
Transcend® Offers a New Perspective with the DrivePro Body 60 Body Camera
Techworld Date Posted: 10:44 AM | 257 Views
Transcend® Information, Inc. (Transcend®), a leading manufacturer of storage and multimedia products, proudly introduces the DrivePro Body 60 body camera. This state-of-the-art POV tethered camera is designed specifically for military and public safety professionals...See More

 
Kingston Technology Celebrates 30 Years Supplying the World with Quality Technology Solutions
Techworld Date Posted: 18 October 2017 1:19 PM | 217 Views
Kingston Technology, a world leader in memory storage products and technology solutions, announces today that it celebrates its 30th year in the business as an innovative technology hardware provider for computers and devices. See More
 
Kingston Technology Celebrates 30 Years Supplying the World with Quality Technology Solutions
Techworld Date Posted: 1:19 PM | 217 Views
Kingston Technology, a world leader in memory storage products and technology solutions, announces today that it celebrates its 30th year in the business as an innovative technology hardware provider for computers and devicesSee More

 
Lenovo Addresses Shifting Workspace Needs
Techworld Date Posted: 23 March 2018 1:11 PM | 334 Views
Lenovo (HKSE: 992) (ADR: LNVGY), the world’s leading PC manufacturer, launched its 8th-generation Lenovo ThinkPads and ThinkStations–specifically designed to provide enhanced agility and performance to support the ever-evolving workspace spurred by millennial workers.. See More
 
Lenovo Addresses Shifting Workspace Needs
Techworld Date Posted: 1:11 PM | 334 Views
Lenovo (HKSE: 992) (ADR: LNVGY), the world’s leading PC manufacturer, launched its 8th-generation Lenovo ThinkPads and ThinkStations–specifically designed to provide enhanced agility and performance to support the ever-evolving workspace spurred by millennial workers.See More

 
Tier One Closes a 7-Figure Foreign Investment to Strengthen Its Presence in South East Asia
Techworld Date Posted: 14 September 2018 3:14 PM | 864 Views
The past few years have seen a widespread boom in the confidence that companies have for esports. Even owners of NBA franchises see the potential that the esports industry has, and have invested heavily.... See More
 
Tier One Closes a 7-Figure Foreign Investment to Strengthen Its Presence in South East Asia
Techworld Date Posted: 3:14 PM | 864 Views
The past few years have seen a widespread boom in the confidence that companies have for esports. Even owners of NBA franchises see the potential that the esports industry has, and have invested heavily...See More

 
Sun Treats Subscribers with Extra 12% Discount at Lazada’s Massive 12.12 Grand Year-End Sale
Techworld Date Posted: 10 December 2018 4:44 PM | 90 Views
It’s the most wonderful time of the year to shop your heart out at Lazada’s 12.12 Grand Year-End Sale — and if you’re with Sun, you can enjoy an extra 12% off on top.... See More
 
Sun Treats Subscribers with Extra 12% Discount at Lazada’s Massive 12.12 Grand Year-End Sale
Techworld Date Posted: 4:44 PM | 90 Views
It’s the most wonderful time of the year to shop your heart out at Lazada’s 12.12 Grand Year-End Sale — and if you’re with Sun, you can enjoy an extra 12% off on top...See More

 
Seven Ways to Ensure a Data Breach Does Not Happen to You
Techworld Date Posted: 12 September 2017 3:18 PM | 272 Views
By: Derek Manky Global Security Strategist,Fortinet 143 million. The number of US consumers potentially affected by the recently announced credit services data breach is staggering. It's nearly half the US population. And as a credit reporting.... See More
 
Seven Ways to Ensure a Data Breach Does Not Happen to You
Techworld Date Posted: 3:18 PM | 272 Views
By: Derek Manky Global Security Strategist,Fortinet 143 million. The number of US consumers potentially affected by the recently announced credit services data breach is staggering. It's nearly half the US population. And as a credit reporting...See More

 
Nokia Mobile Introduces Edge-to-Edge Smartphone Experience
Techworld Date Posted: 16 October 2018 4:05 PM | 121 Views
HMD Global, the home of Nokia phones, has announced the availability of the Nokia 6.1 Plus and the Nokia 5.1 Plus in the Philippines.. See More
 
Nokia Mobile Introduces Edge-to-Edge Smartphone Experience
Techworld Date Posted: 4:05 PM | 121 Views
HMD Global, the home of Nokia phones, has announced the availability of the Nokia 6.1 Plus and the Nokia 5.1 Plus in the Philippines.See More

 
DreamHack and CORSAIR Enter Strategic Partnership
Techworld Date Posted: 15 December 2017 10:06 AM | 241 Views
CORSAIR®, a world leader in enthusiast memory, high-performance gaming hardware and PC components, and DreamHack, the world’s largest digital festival, are excited to announce a groundbreaking new partnership which will see CORSAIR and DreamHack.... See More
 
DreamHack and CORSAIR Enter Strategic Partnership
Techworld Date Posted: 10:06 AM | 241 Views
CORSAIR®, a world leader in enthusiast memory, high-performance gaming hardware and PC components, and DreamHack, the world’s largest digital festival, are excited to announce a groundbreaking new partnership which will see CORSAIR and DreamHack...See More

 
ADATA XPG SPECTRIX D80 RGB Memory Module with Liquid Nitrogen Cooling Hits 5531MHz Mark
Techworld Date Posted: 1 June 2018 10:45 AM | 360 Views
ADATA® Technology, a leading manufacturer of high-performance DRAM modules and NAND Flash products, announces that it has overclocked its XPG SPECTRIX D80 RGB DDR4 memory module to 5531MHz in a liquid-nitrogen-cooled configuration. . See More
 
ADATA XPG SPECTRIX D80 RGB Memory Module with Liquid Nitrogen Cooling Hits 5531MHz Mark
Techworld Date Posted: 10:45 AM | 360 Views
ADATA® Technology, a leading manufacturer of high-performance DRAM modules and NAND Flash products, announces that it has overclocked its XPG SPECTRIX D80 RGB DDR4 memory module to 5531MHz in a liquid-nitrogen-cooled configuration. See More


Power by

Download Free AZ | Free Wordpress Themes