[ad_1]
New crypto-malware builds on the popularity of “Spider-Man: No Way Home”, the latest installment in the series. The film recently had its world premiere and within days, shattered all revenue expectations as it grossed over $ 250 million worldwide in its debut weekend.
Related reading | Huobi Korea drops Monero Over Nth Room case, Bithumb could follow
The excitement generated by the latest Marvel movie was exploited by bad actors, according to a report from ReasonLabs, a cybersecurity firm. Nicknamed the “Spier-Miner”, this malware was created to “lure victims” to a Torrent file with an alleged copy of “No Way Home”.
A torrent, typically downloaded from platforms such as ThePirateBay, is a file shared by many users across the world. Its decentralized nature allows this type of digital documents to bypass censorship, national security agencies, to the benefit or to the detriment of its users.
Reason Security has identified the file as “spiderman_net_putidmoi.torrent.exe”, which stands for “spiderman_no_wayhome.torrent.exe” when translated from Russian. Victims of this crypto-malware will experience the following if they download the file:
This miner adds exclusions to Windows Defender, creates persistence, and spawns a monitoring process to keep it active.
The report further claims that the crypto-malware was designed to evade scrutiny. Therefore, its processes are “written with legitimate names”. The malware, confirmed Reason Security, can “start a process and inject its built-in resources into another process.”
The target is a folder located in the Windows directory. In order to infect and hijack computer resources, the malware decompresses files while running in svchost.exe function. Additionally, the malware is capable of affecting Microsoft Defender, the most commonly used antivirus for Windows computers.
The program starts two powershell encoded commands, which add the following extended exclusions to Microsoft Defender: ignore all folders under user profile, system drive (ie “c: \”), and all files with the “.exe” or “.dll” extensions.
Could you mine for crypto and not know it?
He successfully installed crypto-malware that grabs computer power to mine Monero, a privacy coin that works with totally untraceable transactions. The mining process is kept active via a file called “oocetcmsrfsmni”.
The report claims that it was able to identify the resource responsible for mining once the svchost was analyzed. Into this file, the crypto-malware injected the “xmrig” mining program, the software that runs Monero, as shown in the image below.
PICTURE
The malware is able to remain hidden from programs such as Task Manager, Perfmon, Process Hacker, and Process Explorer. In conclusion, Reason told users the following while still advising:
While this malware does not compromise personal information (which most users fear when they think of a virus on their computer), the damage caused by a miner can be seen in the user’s electricity bill. . It is real money that they have to pay (…)
Related reading | Confirmed: Atomic exchanges between Bitcoin and Monero are a solution. Here is the 411.
At the time of going to press, XMR is trading at $ 205 with a loss of 1.4% over the past 24 hours.
XMR downward trends in the daily chart. Source: XMRUSDT Tradingview
|
Sources 2/ https://bitcoinist.com/spider-man-no-way-home-fans-this-crypto-malware/ The mention sources can contact us to remove/changing this article |
[ad_2]