Kevin Karhan :verified: · @kkarhan
1283 followers · 85365 posts · Server mstdn.social

@kubikpixel Erinnert mich an so manche die sich per non-persistence von Erkennung und Bekämpfung schützt.

ohne sudo und mit geringster Priorität hat extrem schlechte aber langfristiger lohnt es sich für jene Cyberkriminelle unbemerkt weniger Rechenleistung zu 'stehlen' denn binnen weniger Stunden oder Tage von erkannt und von Systemen geworfen zu werden...

#hashrate #xmrig #Malware

Last updated 1 year ago

Redhotcyber · @redhotcyber
400 followers · 577 posts · Server mastodon.bida.im

Un nuovo malware sfrutta le vulnerabilità di Microsoft Exchange per il mining di criptovaluta

Il nuovo , soprannominato “”, sfrutta le di Exchange per distribuire minatori di e trarre profitto dagli aggressori.

Gli aggressori rilasciano quindi il payload del .NET nella cartella del controller di dominio per garantire che tutti i dispositivi sulla possano eseguire il . Per attivarlo è necessario un parametro della riga di comando, che viene duplicato come password per il componente .

redhotcyber.com/post/un-nuovo-

#malware #ProxyShellMiner #vulnerabilità #microsoft #ProxyShell #criptovaluta #Netlogon #rete #xmrig #miner #redhotcyber #informationsecurity #ethicalhacking #dataprotection #hacking #cybersecurity #cybercrime #CyberSecurityAwareness #cybersecuritytraining #CyberSecurityNews #privacy #infosecurity

Last updated 2 years ago

Tarnkappe.info · @tarnkappeinfo
1964 followers · 4226 posts · Server social.tchncs.de
Félix Brezo · @febrezo
156 followers · 213 posts · Server mastodon.social

From a perspective, the would be:

- .003: Command and Scripting Interpreter: Unix Shell. SHC payloads to be run still need a shell to be identified in the system and that the code inside the payload is, in fact, a shell script.
- .002: Obfuscated Files or Information: Software Packed with .
- : Debugger Evasion by using SHC with '-r'.
- : Ingress Tool Transfer by downloading payloads from Github.
- : Resource Hijacking with .

#threatintelligence #ttps #t1059 #t1027 #shc #t1622 #t1105 #t1496 #xmrig

Last updated 2 years ago

Félix Brezo · @febrezo
156 followers · 212 posts · Server mastodon.social

In this regard, I've been working with this evening to understand how it works and I've discovered that it is pretty easy to use it to ship complex scripts onto a single executable file.

The result is Bobominer (github.com/febrezo/bobominer), a stupidly simple PoC of how I've used to create a binary that downloads from Github to download and configure it to start mining.

I didn't expect that it was so easy to package things this way. .

#shc #xmrig #threatintelligence #t1496

Last updated 2 years ago

TribalCyberSecurity · @tribalcyber
13 followers · 16 posts · Server ioc.exchange
k3ym0 · @k3ym0
187 followers · 104 posts · Server infosec.exchange

Yesterday CISA and the FBI published a joint advisory on an Iranian compromising FCEB (Federal Civilian Executive Branch) systems. The threat actors exploited in an unpatched VMware Horizon server, installed crypto mining software, moved laterally to the DC, compromised credentials with , and then backdoored with on several hosts to maintain persistence.

My question is, why the hell they would go out of their way to install XMRig as part of this attack? Was it,

  • for Lulz?
  • to obfuscate their intent?
  • financial motive?

From what I know, "for the Lulz" really isn't part of the APT playbook, and the only APT with financial motive that I'm ware of is North Korea, where cybercrime is literally part of their GNI (Gross National Income). My guess is to obfuscate, but I'd love to hear other people's thoughts on this.

#apt #Log4Shell #xmrig #mimikatz #ngrok #cti #dfir

Last updated 2 years ago

k3ym0 · @k3ym0
266 followers · 128 posts · Server infosec.exchange

Yesterday CISA and the FBI published a joint advisory on an Iranian compromising FCEB (Federal Civilian Executive Branch) systems. The threat actors exploited in an unpatched VMware Horizon server, installed crypto mining software, moved laterally to the DC, compromised credentials with , and then backdoored with on several hosts to maintain persistence.

My question is, why the hell they would go out of their way to install XMRig as part of this attack? Was it,

  • for Lulz?
  • to obfuscate their intent?
  • financial motive?

From what I know, "for the Lulz" really isn't part of the APT playbook, and the only APT with financial motive that I'm ware of is North Korea, where cybercrime is literally part of their GNI (Gross National Income). My guess is to obfuscate, but I'd love to hear other people's thoughts on this.

#apt #Log4Shell #xmrig #mimikatz #ngrok #cti #dfir

Last updated 2 years ago

seadev · @seadev
123 followers · 65 posts · Server infosec.exchange

released an Alert today regarding Iranian Government-Sponsored APT actors
+ exploiting
+ dropping crypto miner
+ leveraging for persistence

us-cert.cisa.gov/ncas/alerts/a

#cisa #Log4Shell #xmrig #ngrok #threatintel #infosec

Last updated 2 years ago

Tarnkappe.info · @tarnkappeinfo
1529 followers · 3787 posts · Server social.tchncs.de
Tarnkappe.info · @tarnkappeinfo
1529 followers · 3787 posts · Server social.tchncs.de
ITSEC News · @itsecbot
856 followers · 32557 posts · Server schleuss.online

Threat Spotlight: "Haskers Gang" Introduces New ZingoStealer - By Edmund Brumaghin and Vanja Svajcer, with contributions from Michael Chen.

Cisco Talos... blog.talosintelligence.com/202

#xmrig #securex #redline #malware #haskersgang #zingostealer #cryptomining #threatspotlight

Last updated 3 years ago

Sozialwelten · @sozialwelten
1532 followers · 10299 posts · Server ifwo.eu

Mit 500 h/s ziemlich langsam auf dem ; Unter ist das Modul nicht verfügbar, das ist neben der Intel Core i5 7400 3.00Ghz vermutlich . hat , ich konnte die Einträge jedoch aus der entfernen. Nicht, dass das jemand würde.

#Arbeitsrechner #wsl #msr #cpu #Flaschenhals #virenscanner #angeschlagen #Logfile #kontrollieren #monero #xmrig

Last updated 3 years ago

Tarnkappe.info · @tarnkappeinfo
1530 followers · 3787 posts · Server social.tchncs.de
ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online
ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online
ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online
ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online
ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online
ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online