Monday, March 3, 2025
HomeCryptocurrency hackHackers using ETERNALBLUE Exploit in Cryptocurrency Mining Malware to Mine Monero...

Hackers using ETERNALBLUE Exploit in Cryptocurrency Mining Malware to Mine Monero using Vulnerable Windows Machines

Published on

SIEM as a Service

Follow Us on Google News

Dubbed Cryptocurrency mining malware PyRoMine using  ETERNALBLUE exploit to hack vulnerable windows based computer to mine Monero cryptocurrency.

ETERNALBLUE is a Remote Code Execution (RCE) exploit that used by shadow brokers who was tied with NSA to abuse the SMBv1 file sharing protocol.

Many of the organization has been used SMB Protocol on the internet during this attack that leveraged those exploits which resulting historical WannaCry and NotPetya ransomware attacks.

PyRoMine Malware written in Python and it comes into stand-alone executables so that it cannot require Python on the targeted computer in order to execute the Python program.

This Malware started in April 2018 and cybercriminals are continuously improving the strength of the malware and this malware had already been paid approximately 2.4 Monero.

Also, PyRoMine Malware equipped to evade the security software and it enables the RDP services in victims machine to open for future attacks.

How Does PyRoMine Malware Mine Monero

Initially, PyRoMine Malware injected into victims computer via malicious URL ( hxxp://212.83.190.122/server/controller.zip) that dropped as a Zip file in the vicitms computer.

Inside of the Zip files contains the python installer that comes with stand-alone executable, once extract the main file, it contains a payload called “controller”

Further Analysis revealed that the Controller file code has been copied from the ETERNALROMANCE exploit.

Later this malware finds the local IP address to find the subnets of the local network to execute the payload.

According to Fortinet Analysis, While ETERNALROMANCE requires authentication, but even for a Guest account the exploit gives the attacker SYSTEM privileges. In the samples analyzed the exploit function is called with an “internal” type parameter.

This Malware login to the target machine using the hardcoded username “Default” and the password “P@ssw0rdf0rme” to execute the payload and also make it as a default credential for re-infection and future attacks.

Later Exploit payload download and execute the VBScript from specific crafted malicious URL that will be responsible for downloading and starting the miner files and setting up the system to Mine the Monero Cryptocurrency.

Finally it Setup a default account in local groups “Administrators,” “Remote Desktop Users,” and “Users.” and enable the RDP port 3389 to allow further traffic from the attacker to perform various malicious activities in future.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Threat Actors Exploiting AES Encryption for Stealthy Payload Protection

Cybersecurity researchers have uncovered a surge in the use of Advanced Encryption Standard (AES)...

33.3 Million Cyber Attacks Targeted Mobile Devices in 2024 as Threats Surge

Kaspersky's latest report on mobile malware evolution in 2024 reveals a significant increase in...

Routers Under Attack as Scanning Attacks on IoT and Networks Surge to Record Highs

In a concerning trend, the frequency of scanning attacks targeting Internet of Things (IoT)...

Google Launches Shielded Email to Keep Your Address Hidden from Apps

Google is rolling out a new privacy-focused feature called Shielded Email, designed to prevent apps...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Winos4.0 Malware Targets Windows Users Through Malicious PDF Files

A new wave of cyberattacks leveraging the Winos4.0 malware framework has targeted organizations in...

Lotus Blossom Hacker Group Uses Dropbox, Twitter, and Zimbra for C2 Communications

The Lotus Blossom hacker group, also known as Spring Dragon, Billbug, or Thrip, has...

Squidoor: Multi-Vector Malware Exploiting Outlook API, DNS & ICMP Tunneling for C2

A newly identified malware, dubbed "Squidoor," has emerged as a sophisticated threat targeting government,...