A cryptojacking campaign uses NSA’s leaked DoublePulsar backdoor and the EternalBlue exploit to spread a file-based cryptocurrency malware on enterprise networks in China. The campaign is most heavily affecting enterprises in Asia, with more than 80 percent of its victims located in China, with other victims in South Korea, Japan, and Vietnam. Almost all of its activity focuses on enterprise environments, this sector recording a 98% infection rate. An earlier version of Beapy targeted a public-facing web server and tries to propagate to computers connected to them.
Source: https://www.bleepingcomputer.com/news/security/eternalblue-exploit-serves-beapy-cryptojacking-campaign/

