Friday, January 31, 2025
HomeBotnetLinux malware that Targets Raspberry Pi for Mining Cryptocurrency

Linux malware that Targets Raspberry Pi for Mining Cryptocurrency

Published on

SIEM as a Service

Follow Us on Google News

Attackers distributing malicious Trojan that infects only Raspberry Pi Minicomputers. These Trojans have a compressed and encrypted application to generate cryptocurrency.

Named as Linux.MulDrop.1, Linux.ProxyM.

Both of the malicious Trojans are examined by Dr.Web Security researchers.

Linux.MulDrop.14

Distribution started in late of may. Once the malware executed it will change the system password as below and then unpack the cryptocurrency miner.

“\$6\$U1Nu9qCp\$FhPuo8s5PsQlH6lwUdTwFcAUPNzmr0pWCdNJj.p6l4Mzi8S867YLmc7BspmEH95POv
xPQ3PzP029yT1L3yi6K1”

Then it goes infinite loop using Zenmap to find network nodes open with port 22, once connection established with SSH it uses sshpass and attempts to log in with user: pi and password: raspberry which is the default username and password.

Also read IoT Botnet Spreading over HTTP Port and Exploiting Security Cameras.

According to Dr.Web Security experts, the infection occurs if the port number 22 kept open and the default password is not changed.

Linux.ProxyM.1

This Trojan used by attackers to ensure there Anonymity. Once launched it will connect to C&C server to get commands from the attacker.

Then it runs a SOCKS proxy server on the infected Machine. Significant attack Over Russia, China, and Taiwan. Illustration of geographical locations for attacked IP’s provided Dr.Web.

This trojan was first noticed by Dr.Web Security experts in February 2017, then it has an enormous growth at the end of May.

Also read Mirai Botnet of 400,000 Bots available for Rental

When compared this to Mirai botnet targeting IoT Devices which explodes in the Mid of April it is far better, both of them use to infect in the same way.

Mirai uses Telnet ports with default username and passwords, whereas Linux.MulDrop.14 uses SSH ports with default username and passwords.

Also Read   Serious Threat: A multi-component Trojan from Linux.LuaBot family infecting Linux devices

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Hackers Exploiting DNS Poisoning to Compromise Active Directory Environments

A groundbreaking technique for Kerberos relaying over HTTP, leveraging multicast poisoning, has been recently...

New Android Malware Exploiting Wedding Invitations to Steal Victims WhatsApp Messages

Since mid-2024, cybersecurity researchers have been monitoring a sophisticated Android malware campaign dubbed "Tria...

500 Million Proton VPN & Pass Users at Risk Due to Memory Protection Vulnerability

Proton, the globally recognized provider of privacy-focused services such as Proton VPN and Proton...

Arcus Media Ransomware Strikes: Files Locked, Backups Erased, and Remote Access Disabled

The cybersecurity landscape faces increasing challenges as Arcus Media ransomware emerges as a highly...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

Murdoc Botnet Exploiting AVTECH Cameras & Huawei Routers to Gain Complete Control

Researchers have identified an active malware campaign involving a Mirai botnet variant, dubbed Murdoc,...

New IoT Botnet Launching Large-Scale DDoS attacks Hijacking IoT Devices

Large-scale DDoS attack commands sent from an IoT botnet's C&C server targeting Japan and...

AIRASHI Botnet Exploiting 0-Day Vulnerabilities In Large Scale DDoS Attacks

AISURU botnet launched a DDoS attack targeting Black Myth: Wukong distribution platforms in August...