According to Kaspersky Lab researchers, cybercriminals have started using sophisticated infection methods and techniques borrowed from targeted attacks in order to install mining software on attacked PCs within organizations. The most successful group observed by Kaspersky Lab earned at least $7 million by exploiting their victims in just six months during 2017.

 

Although the cryptocurrency market is experiencing plenty of ups and downs, last year’s phenomena with surges in the value of Bitcoin has significantly changed not only global economics, but the world of cybersecurity as well. With the aim of earning cryptocurrency, criminals have started to use mining software in their attacks, which, like ransomware, has a simple monetization model.

 

But, unlike ransomware, it doesn’t destructively harm users and is able to stay undetected for a long time by silently using the PC’s power. Back in September 2017, Kaspersky Lab recorded a rise of miners that started actively spreading across the world, and predicted its further development. The latest research reveals that this growth has not only continued, but has also increased and extended.

 

Kaspersky Lab researchers recently identified a cybercriminal group with APT-techniques in their arsenal of tools to infect users with miners. They have been using the process-hollowing method that is usually used in malware and has been seen in some targeted attacks of APT actors, but has never been observed in mining attacks before.

 

The attack works in the following way: the victim is lured into downloading and installing an advertisement software with the miner installer hidden inside. This installer drops a legitimate Windows utility, with the main purpose being to download the miner itself from a remote server.

 

After its execution, a legitimate system process starts, and the legitimate code of this process is changed to malicious code. As a result, the miner operates under the guise of a legitimate task, so it will be impossible for a user to recognize if there is a mining infection.

 

It is also challenging for security solutions to detect this threat. In addition, miners mark this new process through the way it restricts any task cancellation. If the user tries to stop the process, the computer system will reboot. As a result, criminals protect their presence in the system for a longer and more productive time.

 

Based on Kaspersky Lab’s observations, the actors behind these attacks have been mining Electroneum coins and earned almost $7 million during the second half of 2017, which is comparable to the sums that ransomware creators used to earn.

 

We see that ransomware is fading into the background, instead giving way to miners. This is confirmed by our statistics, which show a steady growth of miners throughout the year, as well as by the fact that cybercriminals groups are actively developing their methods and have already started to use more sophisticated techniques to spread mining software. We have already seen such an evolution – ransomware hackers were using the same tricks when they were on the rise,” said Anton Ivanov, Lead Malware Analyst at Kaspersky Lab.

 

Overall, 2.7 million users were attacked by malicious miners in 2017, according to Kaspersky Lab data. That is approximately 50% higher than in 2016 (1.87 mln). They have been falling victims as a result of adware, cracked games and pirated software used by cybercriminals to secretly infect their PCs. Another approach used was web mining through a special code located in an infected web page. The most widely used web miner was CoinHive, discovered on many popular websites.

 

In order to stay protected, Kaspersky Lab recommends that users do the following:

  • Don’t click on unknown websites, or suspicious banners and ads;
  • Do not download and open unknown files from untrusted sources;
  • Install a reliable security solution such as Kaspersky Internet Security or Kaspersky Free that detects and protects you from all possible threats, including malicious mining software.

 

For organizations, Kaspersky Lab recommends the following:

 

More information on miners’ activities can be found on Securelist.com

 

Key trends in mining attacks and the latest discoveries of cryptocurrency threats will be presented at the Security Analyst Summit by Kaspersky Lab researchers, March 9 2018 : https://sas.kaspersky.com/


RECOMMENDED ARTICLE FOR TECHWORLD


 
Free YouTube Promo for Smart, TNT, and Sun Customers Extended until July 31
Techworld Date Posted: 16 July 2018 4:22 PM | 552 Views
PLDT wireless arm Smart Communications, Inc. has announced that it is extending its Free YouTube promo, allowing all prepaid and postpaid customers of Smart, TNT, and Sun to continue enjoying up to one hour.... See More
 
Free YouTube Promo for Smart, TNT, and Sun Customers Extended until July 31
Techworld Date Posted: 4:22 PM | 552 Views
PLDT wireless arm Smart Communications, Inc. has announced that it is extending its Free YouTube promo, allowing all prepaid and postpaid customers of Smart, TNT, and Sun to continue enjoying up to one hour...See More

 
F5 Names Ben Gibson as Chief Marketing Officer
Techworld Date Posted: 4 August 2017 1:11 PM | 283 Views
Business leader with 25 years of experience at Veritas, Aruba Networks, and Cisco Systems to head global marketing team Philippines, August 4, 2016 — F5 Networks (NASDAQ: FFIV), the global leader in application networking and.... See More
 
F5 Names Ben Gibson as Chief Marketing Officer
Techworld Date Posted: 1:11 PM | 283 Views
Business leader with 25 years of experience at Veritas, Aruba Networks, and Cisco Systems to head global marketing team Philippines, August 4, 2016 — F5 Networks (NASDAQ: FFIV), the global leader in application networking and...See More

 
Transcend Is Honored with Five Taiwan Excellence Awards 2019
Techworld Date Posted: 21 November 2018 1:25 PM | 138 Views
Transcend Information, Inc. (Transcend®), a worldwide leader in storage and multimedia products, is proud to announce that five of its state-of-the art products have been awarded the 2019 Taiwan Excellence Award for their innovation.. See More
 
Transcend Is Honored with Five Taiwan Excellence Awards 2019
Techworld Date Posted: 1:25 PM | 138 Views
Transcend Information, Inc. (Transcend®), a worldwide leader in storage and multimedia products, is proud to announce that five of its state-of-the art products have been awarded the 2019 Taiwan Excellence Award for their innovation.See More

 
HyperX Reveals Licensed Headset for PlayStation®4 at ESGS for the First Time in Philippines
Techworld Date Posted: 26 October 2018 4:15 PM | 155 Views
HyperX, the gaming division of Kingston Technology, joins ESGS at the SMX Convention Center, Pasay City in Philippines from October 26th to 28th.. See More
 
HyperX Reveals Licensed Headset for PlayStation®4 at ESGS for the First Time in Philippines
Techworld Date Posted: 4:15 PM | 155 Views
HyperX, the gaming division of Kingston Technology, joins ESGS at the SMX Convention Center, Pasay City in Philippines from October 26th to 28th.See More

 
Getting Ready for the Holidays: Your Safe Online Shopping Guide
Techworld Date Posted: 21 November 2017 8:42 AM | 246 Views
  Online retailers are gearing up for the biggest shopping day of the year. With more consumers doing their holiday shopping online, additional compute resources and warehouses bulging with inventory ensure that shoppers won’t.... See More
 
Getting Ready for the Holidays: Your Safe Online Shopping Guide
Techworld Date Posted: 8:42 AM | 246 Views
  Online retailers are gearing up for the biggest shopping day of the year. With more consumers doing their holiday shopping online, additional compute resources and warehouses bulging with inventory ensure that shoppers won’t...See More

 
Acer Philippines Maintains No. 1 Spot in the PC Market for 10 Years
Techworld Date Posted: 4 March 2019 3:43 PM | 86 Views
The results are in. The growth of the country’s Philippine Personal Computer (PC) market is the fastest in the ASEAN region. Acer leads the Philippine PC market in all circumstances for 10 years straight.... See More
 
Acer Philippines Maintains No. 1 Spot in the PC Market for 10 Years
Techworld Date Posted: 3:43 PM | 86 Views
The results are in. The growth of the country’s Philippine Personal Computer (PC) market is the fastest in the ASEAN region. Acer leads the Philippine PC market in all circumstances for 10 years straight...See More

 
Lax Security Leaves Car Sharing Apps Vulnerable to Attack
Techworld Date Posted: 2 August 2018 1:33 PM | 538 Views
Kaspersky Lab researchers have examined the security of 13 car sharing applications from household manufacturers across the globe – including those from Russia, the US, and Europe.. See More
 
Lax Security Leaves Car Sharing Apps Vulnerable to Attack
Techworld Date Posted: 1:33 PM | 538 Views
Kaspersky Lab researchers have examined the security of 13 car sharing applications from household manufacturers across the globe – including those from Russia, the US, and Europe.See More

 
Industrial Cybersecurity Threat Landscape in H1 2017: Every Third ICS Computer Under Attack Was in Manufacturing Companies
Techworld Date Posted: 14 October 2017 1:53 PM | 311 Views
In the first half of the year manufacturing companies were most susceptible: ICS computers of them accounted for about one-third of all attacks, according to the Kaspersky Lab report “Threat Landscape for Industrial Automation.... See More
 
Industrial Cybersecurity Threat Landscape in H1 2017: Every Third ICS Computer Under Attack Was in Manufacturing Companies
Techworld Date Posted: 1:53 PM | 311 Views
In the first half of the year manufacturing companies were most susceptible: ICS computers of them accounted for about one-third of all attacks, according to the Kaspersky Lab report “Threat Landscape for Industrial Automation...See More

 
ShadowPad: How Attackers Hide Backdoor in Software Used by Hundreds of Large Companies around the World
Techworld Date Posted: 17 August 2017 3:12 PM | 232 Views
Kaspersky Lab experts have discovered a backdoor planted in a server management software product used by hundreds of large businesses around the world. When activated, the backdoor allows attackers to download further malicious modules.... See More
 
ShadowPad: How Attackers Hide Backdoor in Software Used by Hundreds of Large Companies around the World
Techworld Date Posted: 3:12 PM | 232 Views
Kaspersky Lab experts have discovered a backdoor planted in a server management software product used by hundreds of large businesses around the world. When activated, the backdoor allows attackers to download further malicious modules...See More

 
Industry Leading Technology Partners Join the Fortinet Security Fabric Ecosystem
Techworld Date Posted: 23 November 2017 10:28 AM | 307 Views
Fortinet® (NASDAQ: FTNT), the global leader in high-performance cybersecurity solutions, today announced the addition of 11 industry-leading information technology providers to its Fabric-Ready Partner Program. See More
 
Industry Leading Technology Partners Join the Fortinet Security Fabric Ecosystem
Techworld Date Posted: 10:28 AM | 307 Views
Fortinet® (NASDAQ: FTNT), the global leader in high-performance cybersecurity solutions, today announced the addition of 11 industry-leading information technology providers to its Fabric-Ready Partner ProgramSee More


Power by

Download Free AZ | Free Wordpress Themes