Raróg Crypto-Miner Allows Affordable Criminality

Prorootect

Level 69
Thread author
Verified
Nov 5, 2011
5,855
Raróg Crypto-Miner Allows Affordable Criminality

infosecurity-magazine.com: Raróg Crypto-Miner Allows Affordable Criminality

by Tara Seals US/North America News Reporter, Infosecurity Magazine

Raróg - a fire demon.jpg
Raróg - a fire demon.jpg

A cryptocurrency miner Trojan that goes by the name Raróg (a fire demon that originates in Slavic mythology) continues to proliferate, mining unsuspecting victim machines for Monero and other virtual currencies. Its most unusual characteristic is how cheap it is.
Palo Alto Networks’ Unit 42 researchers, which have been following Raróg for months, said that to date, there are roughly 2,500 unique samples in the wild, connecting to 161 different command-and-control (C&C) servers. The firm has confirmed more than 166,000 Raróg-related infections worldwide, mostly in the Philippines, Russia and Indonesia.
Interestingly, the Trojan comes equipped with a number of features, including providing mining statistics to users, configuring various processor loads for the running miner, the ability to infect USB devices and the ability to load additional dynamic-link libraries (DLLs) on the victim. In addition to coin mining, Raróg also employs a number of botnet techniques, including the ability to download and execute other malware, levying distributed denial-of-service (DDoS) attacks against others and updating the Trojan, to name a few.
Despite all this, Raróg provides an affordable way for new criminals to get into the game. Available on various Russian-speaking criminal underground sites, it sells for just $104 at today’s exchange rates.
“The Rarog malware family represents a continued trend toward the use of cryptocurrency miners and their demand on the criminal underground,” the researchers said in a blog. “While not incredibly sophisticated, Rarog provides an easy entry for many criminals into running a cryptocurrency mining botnet. The malware has remained relatively unknown for the past nine months barring a few exceptions. As the value of various cryptocurrencies continues to remain high, it is likely that we’ll continue to see additional malware families with mining functionality surface.”
 
  • Like
Reactions: harlan4096

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top