Tag Archive for: Worm

Unpatched systems at big companies continue to fall to WannaMine worm

Article intro image

Enlarge / This old mine is still yielding somebody Monero. (credit: Max Pixel (CC))

In May of 2017, the WannaCry attack—a file-encrypting ransomware knock-off attributed by the US to North Korea—raised the urgency of patching vulnerabilities in the Windows operating system that had been exposed by a leak of National Security Agency exploits. WannaCry leveraged an exploit called EternalBlue, software that leveraged Windows’ Server Message Block (SMB) network file sharing protocol to move across networks, wreaking havoc as it spread quickly across affected networks.

The core exploit used by WannaCry has been leveraged by other malware authors, including the NotPetya attack that affected companies worldwide a month later, and Adylkuzz, a cryptocurrency-mining worm that began to spread even before WannaCry. Other cryptocurrency-mining worms followed, including WannaMine—a fileless, all-PowerShell based, Monero-mining malware attack that threat researchers have been tracking since at least last October. The servers behind the attack were widely published, and some of them went away.

But a year later, WannaMine is still spreading. Amit Serper, head of security research at Cybereason, has just published research into a recent attack on one of his company’s clients—a Fortune 500 company that Serper told Ars was heavily hit by WannaMine. The malware affected “dozens of domain controllers and about 2,000 endpoints,” Serper said, after gaining access through an unpatched SMB server.

Read 5 remaining paragraphs | Comments

Biz & IT – Ars Technica

Broadcom chip bug opened 1 billion phones to a Wi-Fi-hopping worm attack – Ars Technica UK


Ars Technica UK

Broadcom chip bug opened 1 billion phones to a Wi-Fi-hopping worm attack
Ars Technica UK
But that's just what Nitay Artenstein of Exodus Intelligence did in a feat that affected both iOS and Android devices. At the Black Hat security conference, Artenstein demonstrated proof-of-concept attack code that exploited a vulnerability in Wi-Fi

and more »

android security – read more

GhostCtrl Backdoor Worm Can Silently Hijack Your Android Device – News 24×7


News 24×7

GhostCtrl Backdoor Worm Can Silently Hijack Your Android Device
News 24×7
GhostCtrl Backdoor Worm: In recent days, malware, ransomware, malicious attacks are the biggest problems faced by the global companies. The malware is CopyCat, LeakerLocker and SpyDealer were making the rounds of the Internet, now a new malware …
TrendLabs Security Intelligence BlogAndroid Backdoor GhostCtrl can Silently Record Your Audio, Video, and More …Trend Micro Blogs

all 11 news articles »

android ransomware – read more

EternalRocks network worm uses 7 NSA hacking tools

While you won’t be forgetting the WannaCry ransomware attack, it is likely you will be hearing a lot more about the alleged NSA-linked EternalBlue exploit and DoublePulsar backdoor as it seems a wide range of bad guys have them in their toyboxes. At least one person is leveraging seven leaked NSA hacking tools for a new EternalRocks network worm.

EternalBlue and DoublePulsar

Malwarebytes believes WannaCry did not spread by a malicious spam email campaign, but by an scanning operation that searched for vulnerable public facing SMB ports, then used EternalBlue to get on the network and DoublePulsar to install the ransomware.

To read this article in full or to leave a comment, please click here

Network World Security