Sunday, April 6, 2025
HomeCryptocurrency hackAndroid Based Malicious CryptoMiner Spreading by Worm that has Infected more than...

Android Based Malicious CryptoMiner Spreading by Worm that has Infected more than 5,000 devices in 24 hours

Published on

SIEM as a Service

Follow Us on Google News

A malicious code that reuses Mirai bot spreading by a worm to mine Monero cryptocurrency and this is the first time Android worm reuse Mirai bot.

The infection spreads by scanning the 5555 adb port using the malicious code and this port is used by adb debug interface on Android.

This port should basically shut down on an android device but some case unknown part of the cause led to the wrong port opened.

- Advertisement - Google News

Also Read Cryptocurrency Mining Smominru Botnet Infected more than 500,000 Windows Machines

Devices Infected – Android worm

This Android worm is spreading very actively more than 5,000 devices in 24 hours and it directly infects on adb debug interface in Android and it’s rapidly increasing its traffic.

Based on the initial analyze South Korea and China has reported the major infections especially smartphones, as well as smart TV set-top boxes.

Android worm
According to netlab.360 , the scan traffic on port 5555 starts around 15:00 pm, reaches 3 times the daily background data, and reaches 10 times around 24:00. To date, the number of IPs initiating scanning and the total scanning traffic are still growing.

Mainly affected devices are adb debug interface Android devices and malicious code found that most of the source device based on the Android operating system.

Also, the malicious code contains a script that clearly indicates that it trying to mining Monero.

  • Mine Pool Address: pool.monero.hashvault.pro: 5555 or pool . Minexmr . Com
  • Wallet address (mine account): 44XT4KvmobTQfeWa6PCQF5RDosr2MLWm43AsaE3o5iNR
    XXTfDbYk2VPHTVedTQHZyfXNzMn8YYF2466d3FSDT7gJS8gdHAr
  • Pond password: x

We initially highly suspected that the sample had a worm-like spread. Subsequent analysis confirmed the above speculation from several aspects. Follow-up We may release an update to further illustrate this point. netlab said.

Starting February Smominru botnet affects more than 526,000 windows servers and nodes are distributed worldwide and predominantly in Russia, India, and Taiwan.

The botnet approximately mines 24 Monero every day and researchers said most of them are windows servers that impact critical business infrastructure.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Hack The box “Ghost” Challenge Cracked – A Detailed Technical Exploit

Cybersecurity researcher "0xdf" has cracked the "Ghost" challenge on Hack The Box (HTB), a...

Sec-Gemini v1 – Google’s New AI Model for Cybersecurity Threat Intelligence

Google has unveiled Sec-Gemini v1, an AI model designed to redefine cybersecurity operations by...

U.S. Secures Extradition of Rydox Cybercrime Marketplace Admins from Kosovo in Major International Operation

The United States has successfully extradited two Kosovo nationals, Ardit Kutleshi, 26, and Jetmir...

Ivanti Fully Patched Connect Secure RCE Vulnerability That Actively Exploited in the Wild

Ivanti has issued an urgent security advisory for CVE-2025-22457, a critical vulnerability impacting Ivanti...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Crypto Platform OKX Suspends Tool Abused by North Korean Hackers

Cryptocurrency platform OKX has announced the temporary suspension of its Decentralized Exchange (DEX) aggregator...

Authorities Seize $31 Million Linked to Crypto Exchange Hack

U.S. authorities announced the seizure of $31 million tied to the 2021 Uranium Finance...

Stablecoin Bank Hit by Cyberattack, Loses $49.5M to Hackers

The cryptocurrency sector faced one of its most significant security breaches this year as...