Kaspersky Unveils Powerful Malware Posing as Crypto Miner Infecting Over 1 Million Computers
Source: Pixabay Global cybersecurity and digital privacy firm Kaspersky’s researchers have discovered highly sophisticated malware affecting over a million victims since 2017. The malware – “StripedFly” – initially masqu...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
Global cybersecurity and digital privacy firm Kaspersky’s researchers have discovered highly sophisticated malware affecting over a million victims since 2017.
The malware – “StripedFly” – initially masqueraded as a cryptocurrency miner and was later found to be a complex multi-functional wormable framework. According to the Kaspersky report published Thursday, StripedFly infected over 1 million Windows and Linux computers for five years.
“It comes equipped with a built-in TOR network tunnel for communication with command servers, along with update and delivery functionality through trusted services such as GitLab, GitHub, and Bitbucket, all using custom encrypted archives.”
Kaspersky researchers discovered the malicious framework last year and noted that the effort in creating the framework was “truly remarkable.”
“In 2022, we came across two unexpected detections within the WININIT.EXE process of an older code which was earlier observed in Equation malware,” the researchers wrote. “Subsequent analysis revealed earlier instances of suspicious code dating back to 2017.”
The malware was wrongly classified as just a Monero cryptocurrency miner and it is unclear whether this was utilized for revenue generation or cyber espionage. Experts maintained that the mining module was the key factor enabling the malware to evade detection for a long period.
The findings further added that the attacker behind the malware has acquired extensive capabilities to spy on victims. The malware “collects a range of sensitive information from all active users,” it added.
It extracts website login usernames and passwords and personal autofill data including name, address, phone number, company, and job title. “It also captures known Wi-Fi network names and the associated passwords,” the report revealed.
Similar to EternalBlueStripedFly’s origins remain unknown however further investigations reveal that the malware uses similar techniques as EternalBlue ‘SMBv1’ exploit to infiltrate the victim’s systems.
EternalBlue was leaked in April 2017 and continues to threaten unpatched Windows servers. The infamous exploit was created and used by an NSA hacking group known as the Equation Group.
Kaspersky disclosed that StripedFly was initially detected in April 2016, a year before the EternalBlue detection. In early 2017, Microsoft released a patch for the EternalBlue exploit.
“Created quite some time ago, StripedFly has undoubtedly fulfilled its intended purpose by successfully evading detection over the years. Many high-profile and sophisticated malicious software have been investigated, but this one stands out and truly deserves attention and recognition.”
The post Kaspersky Unveils Powerful Malware Posing as Crypto Miner Infecting Over 1 Million Computers appeared first on Cryptonews.
Why this matters
This mining story adds another data point to the current market tape and is useful when read alongside nearby source coverage.
Original source
Read on CryptonewsRelated market context
Locked liquidity did not stop this $14 million crypto pool drain
The PancakeSwap pool for 79AU, 79thVault’s token, lost $14.35 million in USDT on Oct. 7 through two selling wallets, according to...
Bitcoin miners escape months of distress as daily revenue surges by 78%
Bitcoin miners are emerging from months of financial pressure as rising BTC prices lift daily industry revenue by 78%. According t...
BNB Chain Hits 2 Million RWA Holders, Capturing 40% of Onchain Market
BNB Chain has become the first blockchain to surpass 2 million holders of tokenized real-world assets (RWAs), giving it roughly 40...
Ledger hack scare nears $90 million as Tether moves to freeze stolen USDT
Suspected Ledger wallet thefts are approaching $90 million as Tether freezes USDT stablecoin linked to the incident, according to...
Circle minted another 750 million USDC on Solana in the last 24 hours
Increased USDC liquidity on Solana may boost SOL demand, but its market impact depends on active circulation and broader crypto tr...
Tether froze 1.45 million USDT in THORChain vaults, then reversed course three hours later
The incident highlights the vulnerability of DeFi protocols to centralized issuer actions, emphasizing the need for diversified as...