Blog | G5 Cyber Security

PyRoMineIoT spreads via EternalRomance exploit and targets targets IoT devices in Iran and Saudi Arabia.

Fortinet discovered PyRoMineIoT, a new strain of crypto-currency miner that exploits the NSA-linked EternalRomance exploit to spread. The malware also abuses infected machines to scan for vulnerable Internet of Things devices. It is delivered from a website disguised as security updates for web browsers. Analysis of one of the pool addresses used by the threat actors behind the malware revealed it earned around 5 Monero (about $850). Another component is a tool that steals user credentials from Chrome browser named ChromePass.”]

Source: https://securityaffairs.co/wordpress/73472/malware/pyromineiot-iot-miner.html

Exit mobile version