Get a Pentest and security assessment of your IT network.

Cyber Security

Monero-mining botnet targets orgs through recent MS Exchange vulnerabilities

Prometei is a cross-platform (Windows, Linux), modular Monero-mining botnet that seems to have flown under the radar for years. Cybereason incident responders have witnessed instances of the botnet enslaving endpoints of companies across the globe, in a variety of industries. The malware is specifically interested in the file ‘ExpiredPasswords.aspx’, which was reported to be the name used to obscure the HyperShell backdoor used by APT34 (aka. OilRig) If the file exists, the malware immediately deletes it, and uses a module that masquerades as a legitimate Microsoft endpoint security program.

Source: https://www.helpnetsecurity.com/2021/04/22/botnet-exchange-vulnerabilities/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security