According to Kaspersky Lab researchers, cybercriminals have started using sophisticated infection methods and techniques borrowed from targeted attacks in order to install mining software on attacked PCs within organizations. The most successful group observed by Kaspersky Lab earned at least $7 million by exploiting their victims in just six months during 2017.

 

Although the cryptocurrency market is experiencing plenty of ups and downs, last year’s phenomena with surges in the value of Bitcoin has significantly changed not only global economics, but the world of cybersecurity as well. With the aim of earning cryptocurrency, criminals have started to use mining software in their attacks, which, like ransomware, has a simple monetization model.

 

But, unlike ransomware, it doesn’t destructively harm users and is able to stay undetected for a long time by silently using the PC’s power. Back in September 2017, Kaspersky Lab recorded a rise of miners that started actively spreading across the world, and predicted its further development. The latest research reveals that this growth has not only continued, but has also increased and extended.

 

Kaspersky Lab researchers recently identified a cybercriminal group with APT-techniques in their arsenal of tools to infect users with miners. They have been using the process-hollowing method that is usually used in malware and has been seen in some targeted attacks of APT actors, but has never been observed in mining attacks before.

 

The attack works in the following way: the victim is lured into downloading and installing an advertisement software with the miner installer hidden inside. This installer drops a legitimate Windows utility, with the main purpose being to download the miner itself from a remote server.

 

After its execution, a legitimate system process starts, and the legitimate code of this process is changed to malicious code. As a result, the miner operates under the guise of a legitimate task, so it will be impossible for a user to recognize if there is a mining infection.

 

It is also challenging for security solutions to detect this threat. In addition, miners mark this new process through the way it restricts any task cancellation. If the user tries to stop the process, the computer system will reboot. As a result, criminals protect their presence in the system for a longer and more productive time.

 

Based on Kaspersky Lab’s observations, the actors behind these attacks have been mining Electroneum coins and earned almost $7 million during the second half of 2017, which is comparable to the sums that ransomware creators used to earn.

 

We see that ransomware is fading into the background, instead giving way to miners. This is confirmed by our statistics, which show a steady growth of miners throughout the year, as well as by the fact that cybercriminals groups are actively developing their methods and have already started to use more sophisticated techniques to spread mining software. We have already seen such an evolution – ransomware hackers were using the same tricks when they were on the rise,” said Anton Ivanov, Lead Malware Analyst at Kaspersky Lab.

 

Overall, 2.7 million users were attacked by malicious miners in 2017, according to Kaspersky Lab data. That is approximately 50% higher than in 2016 (1.87 mln). They have been falling victims as a result of adware, cracked games and pirated software used by cybercriminals to secretly infect their PCs. Another approach used was web mining through a special code located in an infected web page. The most widely used web miner was CoinHive, discovered on many popular websites.

 

In order to stay protected, Kaspersky Lab recommends that users do the following:

  • Don’t click on unknown websites, or suspicious banners and ads;
  • Do not download and open unknown files from untrusted sources;
  • Install a reliable security solution such as Kaspersky Internet Security or Kaspersky Free that detects and protects you from all possible threats, including malicious mining software.

 

For organizations, Kaspersky Lab recommends the following:

 

More information on miners’ activities can be found on Securelist.com

 

Key trends in mining attacks and the latest discoveries of cryptocurrency threats will be presented at the Security Analyst Summit by Kaspersky Lab researchers, March 9 2018 : https://sas.kaspersky.com/


RECOMMENDED ARTICLE FOR TECHWORLD


 
Realme Philippines Introduces C1 – the #RealEntryLevelKing Smartphone
Techworld Date Posted: 29 November 2018 5:16 PM | 136 Views
Realme, an expert in providing high-quality smartphones for the youth, marks its entry into the Philippine market with its first smartphone aimed at the local market, the Realme C1.. See More
 
Realme Philippines Introduces C1 – the #RealEntryLevelKing Smartphone
Techworld Date Posted: 5:16 PM | 136 Views
Realme, an expert in providing high-quality smartphones for the youth, marks its entry into the Philippine market with its first smartphone aimed at the local market, the Realme C1.See More

 
HyperX Ships 60 Million Memory Modules
Techworld Date Posted: 23 October 2018 10:31 AM | 168 Views
HyperX, the gaming division of Kingston Technology Company, Inc. has announced that since its inception in 2002, it has shipped over 60 million memory modules, which is equivalent to billions of bytes of memory.. See More
 
HyperX Ships 60 Million Memory Modules
Techworld Date Posted: 10:31 AM | 168 Views
HyperX, the gaming division of Kingston Technology Company, Inc. has announced that since its inception in 2002, it has shipped over 60 million memory modules, which is equivalent to billions of bytes of memory.See More

 
TRIAL and ERROR: Kaspersky Lab Unearths iOS Cryptomining Attacks, Careless Mistakes by Roaming Mantis
Techworld Date Posted: 24 September 2018 4:57 PM | 221 Views
Just five months after Kaspersky Lab’s first report on the DNS hijacking operation to infect Android smartphones in Asia, the attack dubbed ‘Roaming Mantis’ remains highly active, exploring new tricks and techniques to extend.... See More
 
TRIAL and ERROR: Kaspersky Lab Unearths iOS Cryptomining Attacks, Careless Mistakes by Roaming Mantis
Techworld Date Posted: 4:57 PM | 221 Views
Just five months after Kaspersky Lab’s first report on the DNS hijacking operation to infect Android smartphones in Asia, the attack dubbed ‘Roaming Mantis’ remains highly active, exploring new tricks and techniques to extend...See More

 
Nokia 8 Flagship Android Smartphone Arrives in PH
Techworld Date Posted: 30 September 2017 11:39 AM | 311 Views
Ending weeks of anticipation, HMD Global unveils Nokia's new flagship smartphone, the Nokia 8, today at the Intramuros Ballroom, Manila House, Taguig.. See More
 
Nokia 8 Flagship Android Smartphone Arrives in PH
Techworld Date Posted: 11:39 AM | 311 Views
Ending weeks of anticipation, HMD Global unveils Nokia's new flagship smartphone, the Nokia 8, today at the Intramuros Ballroom, Manila House, Taguig.See More

 
Fortinet Introduces New Security Automation Capabilities on Amazon Web Services, Expands Fortinet Security Fabric Offerings
Techworld Date Posted: 4 January 2019 1:19 PM | 155 Views
Fortinet® (NASDAQ: FTNT), a global leader in broad, integrated and automated cybersecurity solutions, has announced the expansion of its Fortinet Security Fabric offerings and new automation capabilities for Amazon Web Services (AWS). See More
 
Fortinet Introduces New Security Automation Capabilities on Amazon Web Services, Expands Fortinet Security Fabric Offerings
Techworld Date Posted: 1:19 PM | 155 Views
Fortinet® (NASDAQ: FTNT), a global leader in broad, integrated and automated cybersecurity solutions, has announced the expansion of its Fortinet Security Fabric offerings and new automation capabilities for Amazon Web Services (AWS)See More

 
Watch and Enjoy The International Pubstomp 2017 the right Way
Techworld Date Posted: 10 August 2017 2:28 PM | 324 Views
   – Join MSI Gaming as they bring you #TI7 Viewing Party at Club Nix05 from 10pm of Saturday, August 12th, until Sunday dawn!   Gain EXCLUSIVE access to Official TI7 Merchandise available.... See More
 
Watch and Enjoy The International Pubstomp 2017 the right Way
Techworld Date Posted: 2:28 PM | 324 Views
   – Join MSI Gaming as they bring you #TI7 Viewing Party at Club Nix05 from 10pm of Saturday, August 12th, until Sunday dawn!   Gain EXCLUSIVE access to Official TI7 Merchandise available...See More

 
Power Mac Center’s Official Statement on the iPhone Battery Servicing
Techworld Date Posted: 22 January 2018 2:45 PM | 271 Views
In light of Apple’s official communication regarding the chemical aging issue of batteries on older iPhone units, Power Mac Center,. See More
 
Power Mac Center’s Official Statement on the iPhone Battery Servicing
Techworld Date Posted: 2:45 PM | 271 Views
In light of Apple’s official communication regarding the chemical aging issue of batteries on older iPhone units, Power Mac Center,See More

 
Unlocking Insights for Sustainable Development in ASEAN with Data and Analytics
Techworld Date Posted: 15 December 2017 10:19 AM | 290 Views
Data has become the new life force that drives the world today. Businesses have always leveraged their company or customer information to make better, smarter, real time, fact-based decisions – from developing a new.... See More
 
Unlocking Insights for Sustainable Development in ASEAN with Data and Analytics
Techworld Date Posted: 10:19 AM | 290 Views
Data has become the new life force that drives the world today. Businesses have always leveraged their company or customer information to make better, smarter, real time, fact-based decisions – from developing a new...See More

 
How We (Lenovo) See a World Powered by AI
Techworld Date Posted: 28 July 2017 3:54 PM | 360 Views
Ask 10 people what does AI do, and you'll likely get 10 different answers. And many of them would be correct. That's the beauty of AI; it's capable of so many things.. See More
 
How We (Lenovo) See a World Powered by AI
Techworld Date Posted: 3:54 PM | 360 Views
Ask 10 people what does AI do, and you'll likely get 10 different answers. And many of them would be correct. That's the beauty of AI; it's capable of so many things.See More

 
D-Link Powers PLDT Fam Cam Line with Latest Security Cameras
Techworld Date Posted: 18 May 2019 9:21 AM | 29 Views
D-Link International Pte. Ltd., leading global provider of networking products, teams up with PLDT Home Fam Cam, the telco giant’s home monitoring system, to bring Filipinos better home and office security through two new.... See More
 
D-Link Powers PLDT Fam Cam Line with Latest Security Cameras
Techworld Date Posted: 9:21 AM | 29 Views
D-Link International Pte. Ltd., leading global provider of networking products, teams up with PLDT Home Fam Cam, the telco giant’s home monitoring system, to bring Filipinos better home and office security through two new...See More


Power by

Download Free AZ | Free Wordpress Themes