Huawei Cloud targeted by updated cryptomining malware

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Forum Veteran
Feb 4, 2016
2,516
15,624
3,578
53
Germany / Poland
A new version of a Linux crypto-mining malware previously used to target Docker containers in 2020 now focuses on new cloud service providers like the Huawei Cloud.
The analysis of the new campaign comes from researchers at TrendMicro, who explains how the malware has evolved with new features while retaining its previous functionality.
More specifically, the newer samples have commented out the firewall rules creation function (but it's still there) and continue to drop a network scanner to map other hosts with API-relevant ports.
 
  • Like
Reactions: The_King