Tuesday, April 8, 2025
HomeMalwarePowerGhost Malware Remotely Attack Corporate Network Servers & Workstations using EternalBlue Exploit

PowerGhost Malware Remotely Attack Corporate Network Servers & Workstations using EternalBlue Exploit

Published on

SIEM as a Service

Follow Us on Google News

Newly discovered  PowerGhost Malware Spreading across corporate networks that infecting both servers and workstations to illegally mining the crypt-currency and Perform DDoS Attacks.

Cybercriminals targeting large number corporate networks to mining the cryptocurrency and DDoS attack to generate huge profits.

Enterprise Networks should choose the best DDoS Attack prevention services to ensure the DDoS attack protection and prevent their network.

- Advertisement - Google News

In this case, attackers using fileless malware techniques to maintain the persistence and it used to bypass the antivirus detection and leverage the corporate vulnerabilities using known exploits such as Eternalblue.

PowerGhost malware miner is encountered most often in India, Brazil, Columbia, and Turkey and infected a large number of corporate companies local area networks.

PowerGhost Malware Infection Techniques

Initially, victims affected using remote administration tools or remotely using exploits and the PowerShell scripts will download the miner’s and immediately launches it into the hard drive.

PowerGhost act as an Obfuscated PowerShell scripts that contains a number of core modules such as miners, libraries for mining operations and PE file injection for Eternalblue exploit.

  • Miner – mimikatz
  • libraries – msvcp120.dll and msvcr120.dll
  • PE injection and shellcode

Scripts performing the several stages and it is capable of self-update its module that keeps checking its C2 server, if it found any, then it automatically update itself.

According to kaspersky , With the help of mimikatz, the miner obtains the user account credentials from the current machine, uses them to log on and attempts to propagate across the local network by launching a copy of itself via WMI and download the miner body from C2 server.

PowerGhost try to spread across the local network using the EternalBlue exploit (MS17-010, CVE-2017-0144).

Later it escalates its privileges when it landing into the new system with the 32- or 64-bit exploits for MS16-032, MS15-051, and CVE-2018-8120. Finally, the script launches the miner by loading a PE file via reflective PE injection.

Researchers also found a tool for conducting DDoS attacks in one of the PowerGhost version to make extra money along with the mining operation profit.

Protect your corporate networks from future attacks and also Check your Companies DDOS Attack Downtime Cost.

Indicators of compromise

MD5:

AEEB46A88C9A37FA54CA2B64AE17F248
4FE2DE6FBB278E56C23E90432F21F6C8
71404815F6A0171A29DE46846E78A079
81E214A4120A4017809F5E7713B7EAC8

Also Read

Hackers Mined Monero Worth $90000 by Pushing 17 Malicious Images to a Docker Hub

Hackers using ETERNALBLUE Exploit in Cryptocurrency Mining Malware to Mine Monero using Vulnerable Windows Machines

The Pirate Bay Mining Monero Cryptocurrency – Beware & Here the Best TPB Alternative 2018

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Threat Actors Exploit Toll Payment Services in Widespread Hacking Campaign

In a sophisticated cybercrime operation, the Smishing Triad, a China-based group, has been identified...

Everest Ransomware Gang’s Leak Site Hacked and Defaced

TechCrunch has uncovered a concerning development in consumer-grade spyware: a stealthy Android monitoring app...

ToddyCat Attackers Exploited ESET Command Line Scanner Vulnerability to Conceal Their Tool

In a sophisticated cyberattack, the notorious ToddyCat APT group utilized a previously unknown vulnerability...

Threat Actors Use VPS Hosting Providers to Deliver Malware and Evade Detection

Cybercriminals are intensifying phishing campaigns to spread the Grandoreiro banking trojan, targeting users primarily...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Threat Actors Use VPS Hosting Providers to Deliver Malware and Evade Detection

Cybercriminals are intensifying phishing campaigns to spread the Grandoreiro banking trojan, targeting users primarily...

Auto-Color Linux Backdoor: TTPs and Internal Architecture Exposed

A newly identified Linux backdoor named "Auto-Color," first observed between November and December 2024,...

Threat Actors Exploit Fake CAPTCHAs and Cloudflare Turnstile to Distribute LegionLoader

In a sophisticated attack targeting individuals searching for PDF documents online, cybercriminals are using...