Cybercriminals spotted hiding cryptocurrency mining malware in forked projects on GitHub

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Feb 4, 2016
2,520
Those behind the campaign are tailoring the Monero cryptojacking malware to use a limited amount of CPU power in order to evade infections being detected.

Cybercriminals have found another way to spread their malware: uploading cryptocurrency mining code to GitHub, according to security researchers at security company Avast.

Developers 'fork' projects on GitHub, which means making a copy of someone else's project in order to build on it. In this case, the cybercriminals fork random projects and then hide malicious executables in the directory structure of these new projects, the researchers said.

Users don't need to download the malicious executables directly from GitHub. Instead, the malware is spread via a phishing ad campaign. When a user visits a site that displays the phishing ads and clicks on one, the executable downloads, the researchers said.

If the user clicks on one of these adverts, they're told their Flash Player is out of date and provided with a fake update which, if downloaded, will infect them with the malware. This update is provided via a redirect to GitHub, where the code is hosted, hidden in forked projects.

While hosting malware on GitHub is described by researchers as "unusual", they point to it being beneficial to the attackers because it offers unlimited bandwidth.

In addition to this, the malware also installs a malicious Chrome extension which injects and clicks on adverts in the background, allowing attackers to extract even more profit from the cryptojacking campaign.

The malware itself is primarily designed for mining Monero, an increasingly popular cryptocurrency for criminals as it's both easy to mine and offers a range of privacy benefits.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top