Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Security Management

5/21/2018
08:05 AM
Jeffrey Burt
Jeffrey Burt
Jeffrey Burt
50%
50%

Check Point: Cryptomining Malware Targeting Vulnerable Servers

As the incidence of ransomware wanes, attackers are shifting to cryptocurrency mining malware as a less noisy, more lucrative alternative, according to a new Check Point study.

Cryptomining in some ways has become the new ransomware, the latest focus for cyber attackers looking to make money by infiltrating users' computers, according to researchers at Check Point Software.

In the security company's latest Global Threat Index for April, researchers wrote that the activity around cryptomining malware has shot up since the end of 2017 and into the first four months of this year, most recently with attackers increasingly targeting unpatched vulnerabilities Microsoft and Oracle servers. It's part of a larger shift of cybercriminals trending away from ransomware to find another way to make money, according to Omer Dembinsky, data research team leader for Check Point's Threat Intelligence Group.

The incidence of ransomware in recent months has waned somewhat, although the malware is still a threat.

It took off a year ago with the emergence of the WannaCry worm, which in turn led to other ransomware malware like NotPetya, BadRabbit and Olympic Destroyer. However, ransomware is highly disruptive and noisy -- once it's in the machine, the user knows it's there -- and it usually required action on the user's part, including creating a Bitcoin account and then paying the ransom, Dembinsky told Security Now. (See WannaCry: How the Notorious Worm Changed Ransomware.)

"Cryptomining is a very lucrative path for that because it's basically very silent in the background," he said. "Users might not notice it, although it is something that can slow the computer down [and] it can hurt the applications running, but basically [it] can run uninterrupted by the user, can be there more persistently over a long time, so that's probably what led it to being a leading vector for attack. And the threat actors don't need a lot of knowledge in building sophisticated malware. They just put in a short part of code, they just run a small script, and that's it." (See Cryptocurrency Theft Uses Old Exploit to Highjack AWS Traffic.)

Cryptomining increasing
April was the fourth consecutive month where cryptomining malware dominated Check Point's list of the top malware threats, claiming the top spots. At number one was Coinhive, used to mine Monero cryptocurrency, while Cryptoloot was second. According to Check Point, the malware leverages a system's CPU or GPU power and other resources to add transactions to the blockchain and release new currency. Coinhive had a 16% global reach; Cryptoloot at a 14% reach.

In a blog post in March, Symantec's Security Response Team noted that detections of cryptocurrency coin mining began to skyrocket in September 2017, from well below 100,000 detections that month to more than 170,000 detections in December.

"Cyber criminals use coinminers to steal victims' computer processing power and cloud CPU usage to mine cryptocurrencies," the Symantec team wrote. "The barrier to entry for coin mining is pretty low -- potentially only requiring a couple of lines of code to operate -- and coin mining can allow criminals to lay under the radar in a way that is not possible with other types of cyber crime."

It's why attackers are now looking for server vulnerabilities to exploit, Check Point's Dembinsky said.

In April, the security firm saw a significant jump in cybercriminals targeting vulnerabilities in servers running Windows Server 2003 and Oracle Web Logic. Patches from Microsoft and Oracle have been available for at least six months, but threat actors continue to look for servers they can get into. According to Check Point, cybercriminals targeted 46% of organizations worldwide for the Windows Server 2013 vulnerability, while 40% of such organizations were targeted for the Web Logic vulnerability.

"What we've been seeing is basically they're trying to find any available CPUs or computers to run on," Dembinsky said. "Personal computers and corporate computers and mobile phones [have been targeted in the past] and, of course, servers have even much larger CPU and computing resources. That's very helpful for what they need. They can run much more on it. It's not necessarily something that's new, but it's one vector they're trying to exploit much more heavily."

Need for patching
Given the success attackers have had with cryptomining, it's likely the trend will continue for a while. Users won't always know when the malware is running on their systems, and that enables it to run for longer periods of time than noisier attacks like ransomware. That said, eventually something new will arise that will be a new popular avenue for cybercriminals, he said.

The attacks on the unpatched vulnerabilities of some Windows and Oracle servers highlights the need for organizations to be vigilant in keeping up-to-date with patching. Dembinsky pointed to WannaCry as an example, noting that its initial point of entry into systems as through a vulnerability that Microsoft had patched months earlier.

Protecting servers from cryptomining malware by patching the systems also is critical.

"We're talking about a big wave of trying to find servers that weren't patched," Dembinsky said. "So [attackers are] going out at about half of the networks in the world, and then once the criminals are able to find 1% or 2% that weren't patched, that still leaves them with thousands and thousands of networks, and inside each network, you can find thousands and thousands of machines and computers, so that is a lot of work that they can utilize to their goals."

Related posts:

— Jeffrey Burt is a long-time tech journalist whose work has appeared in such publications as eWEEK, The Next Platform and Channelnomics.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/17/2020
Cybersecurity Bounces Back, but Talent Still Absent
Simone Petrella, Chief Executive Officer, CyberVista,  9/16/2020
Meet the Computer Scientist Who Helped Push for Paper Ballots
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/16/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-8225
PUBLISHED: 2020-09-18
A cleartext storage of sensitive information in Nextcloud Desktop Client 2.6.4 gave away information about used proxies and their authentication credentials.
CVE-2020-8237
PUBLISHED: 2020-09-18
Prototype pollution in json-bigint npm package < 1.0.0 may lead to a denial-of-service (DoS) attack.
CVE-2020-8245
PUBLISHED: 2020-09-18
Improper Input Validation on Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11....
CVE-2020-8246
PUBLISHED: 2020-09-18
Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-W...
CVE-2020-8247
PUBLISHED: 2020-09-18
Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-W...