Brian Krebs Fan Creates New Cryptocurrency Miner for Linux Devices

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Feb 4, 2016
2,520
A malware author has created a new cryptocurrency miner that infects Linux devices that use open or default Telnet credentials.

This new trojan — detected by Dr.Web under the name Linux.BTCMine.26 (BTCMine in the rest of this article) — mines for the Monero cryptocurrency and targets only the x86-64 and ARM hardware architectures.

Miner infects Linux devices via unsecured Telnet ports
Researchers say the trojan uses a Telnet scanner similar to the one deployed by the Mirai IoT malware. BTCMine will scan random IPv4 addresses and attempt to connect via the Telnet port.

If the port is open or the user employs one of many known default credentials, the malware connects and runs commands to download and run the actual BTCMine binary.

The trojan stood out in the eyes of Dr.Web researchers because of the many references to krebsonsecurity.com, the personal blog of infosec investigative journalist Brian Krebs.

This is not the first malware to reference Krebs or his blog, both very popular both among security researchers and malware authors alike. In recent years, it's become quite commonplace for malware developers to insult or give Krebs a shout out in their code.
 
  • Like
Reactions: Wingman and ispx

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top