Blog | G5 Cyber Security

Mining Smominru botnet used NSA exploit to infect more than 526,000 systems

Researchers from Proofpoint discovered a huge botnet dubbed Smominru (aka Ismo) that is using the EternalBlue exploit (CVE-2017-0144) to infect Windows computers and recruit them in Monero mining activities. The Smominru botnet has been active at least since May 2017 and has already infected more than 526,000 Windows computers. Most of the infected systems are servers distributed worldwide, most of them in Russia, India, and Taiwan.”]

Source: https://securityaffairs.co/wordpress/68494/malware/smominru-botnet.html

Exit mobile version