Two days ago when infosec bods claimed to have uncovered what's believed to be the first case of a SCADA network (a water utility) infected with cryptocurrency-mining malware, a batch of journalists accused other authors of making fear-mongering headlines, taunting that the next headline could be about cryptocurrency-miner detected in a nuclear plant.
It seems that now they have to run a story themselves with such headlines on their website because Russian Interfax News Agency yesterday reported that several scientists at Russia's top nuclear research facility had been arrested for mining cryptocurrency with "office computing resources."
The suspects work as engineers at the Russian Federation Nuclear Center facility—also known as the All-Russian Research Institute of Experimental Physics—which works on developing nuclear weapons.
The center is located in Sarov, Sarov is still a restricted area with high security. It is also the birthplace of the Soviet Union's first nuclear bomb.
In 2011, the Russian Federation Nuclear Center switched on a new supercomputer with a capacity of 1 petaflop, making it the twelfth most powerful in the world at the time.
According to Russian media reports, the engineers had tried to use one of Russia's most powerful supercomputers housed in the Federal Nuclear Center to mine Bitcoins.
The suspects were caught red-handed while attempting to connect the lab's supercomputer to the internet, which was supposed to be offline to ensure security, the nuclear center's security department was alerted.
Once caught, the engineers were handed over to the Federal Security Service (FSB).
"There has been an unsanctioned attempt to use computer facilities for private purposes including so-called mining," Tatyana Zalesskaya, head of the Institute's press service, told Interfax news agency.
"Their activities were stopped in time. The bungling miners have been detained by the competent authorities. As far as I know, a criminal case has been opened regarding them," Zalesskaya added, without revealing the exact number of employees detained.
The Federal Security Service (FSB) has yet to issue a statement on the arrests and criminal charges.
Cryptocurrency has gained tremendous popularity over the past year. Mining a single Bitcoin is not an ice cakewalk, as it requires an enormous amount of computational power and huge amounts of energy.
According to media reports, Russia is becoming a hotbed of cryptocurrency mining due to its low-cost energy reserves. One Russian businessman, Alexey Kolesnik, reportedly also bought two power stations exclusively to generate electricity for Bitcoin-mining data centers.
Source: TheHackerNews
Russian Scientists Arrested for Using Nuclear Weapon Facility to Mine Bitcoins
Cryptocurrency Mining Malware Infected Over Half-Million PCs Using NSA Exploit
2017 was the year of high profile data breaches and ransomware attacks, but from the beginning of this year, we are noticing a faster-paced shift in the cyber threat landscape, as cryptocurrency-related malware is becoming a popular and profitable choice of cyber criminals.
Several cybersecurity firms are reporting of new cryptocurrency mining viruses that are being spread using EternalBlue—the same NSA exploit that was leaked by the hacking group Shadow Brokers and responsible for the devastating widespread ransomware threat WannaCry.
Researchers from Proofpoint discovered a massive global botnet dubbed "Smominru," a.k.a Ismo, that is using EternalBlue SMB exploit (CVE-2017-0144) to infect Windows computers to secretly mine Monero cryptocurrency, worth millions of dollars, for its master.
Active since at least May 2017, Smominru botnet has already infected more than 526,000 Windows computers, most of which are believed to be servers running unpatched versions of Windows, according to the researchers.
"Based on the hash power associated with the Monero payment address for this operation, it appeared that this botnet was likely twice the size of Adylkuzz," the researchers said.
The botnet operators have already mined approximately 8,900 Monero, valued at up to $3.6 million, at the rate of roughly 24 Monero per day ($8,500) by stealing computing resources of millions of systems.
The highest number of Smominru infection has been observed in Russia, India, and Taiwan, the researchers said.
The command and control infrastructure of Smominru botnet is hosted on DDoS protection service SharkTech, which was notified of the abuse but the firm reportedly ignored the abuse notifications.
According to the Proofpoint researchers, cybercriminals are using at least 25 machines to scan the internet to find vulnerable Windows computers and also using leaked NSA's RDP protocol exploit, EsteemAudit (CVE-2017-0176), for infection.
"As Bitcoin has become prohibitively resource-intensive to mine outside of dedicated mining farms, interest in Monero has increased dramatically. While Monero can no longer be mined effectively on desktop computers, a distributed botnet like that described here can prove quite lucrative for its operators," the researchers concluded.
"The operators of this botnet are persistent, use all available exploits to expand their botnet, and have found multiple ways to recover after sinkhole operations. Given the significant profits available to the botnet operators and the resilience of the botnet and its infrastructure, we expect these activities to continue, along with their potential impacts on infected nodes."
Another security firm CrowdStrike recently published a blog post, reporting another widespread cryptocurrency fileless malware, dubbed WannaMine, using EternalBlue exploit to infect computers to mine Monero cryptocurrency.
Since it does not download any application to an infected computer, WannaMine infections are harder to detect by antivirus programs.
CrowdStrike researchers observed the malware has rendered "some companies unable to operate for days and weeks at a time."
Besides infecting systems, cybercriminals are also widely adopting cryptojacking attacks, wherein browser-based JavaScript miners utilise website visitors' CPUs power to mine cryptocurrencies for monetisation.
Since recently observed cryptocurrency mining malware attacks have been found leveraging EternalBlue, which had already been patched by Microsoft last year, users are advised to keep their systems and software updated to avoid being a victim of such threats.
Source: The HackerNews
South Korea Considers a Bitcoin Ban, Sparking Outrage
South Korean regulators are mulling a ban on cryptocurrency trading, sparking outrage across the nation.
The justice minister, Park Sang-ki, said this week that the government was preparing legislation to halt the trading of Bitcoin, Monero and other virtual money.
Trading is a popular pastime in South Korea, the world’s most wired country. Its young, tech-savvy populace has seized on virtual currency as a way to earn cash amid an economy that offers dwindling job prospects for millennials, despite its relative wealth as a nation. With Bitcoin pricing exploding over the last few months, many people have earned quite a bit. About a third of the 941 office workers surveyed in December by Saramin, a South Korea-based job portal, have traded virtual currency; out of those, more than 80% made money from it, and about 20% made a whopping average return of 425% on their investment, according to the survey.
The average Korean investor owns around 5.66 million won ($5,260) in virtual currencies.
“Tax it as much as you want but don’t shut it down. My life depends on it,” one petitioner wrote on the president’s website, according to Reuters. The petition there has drawn more than 120,000 signatures against a ban, as of Friday.
Regulators are concerned that the casino-like, speculative nature of the virtual marketplace has resulted in a bubble that is destined to burst, and they worry that economic catastrophe for whole swaths of the population could follow.
“On one hand, there is a growing part of their population who has adopted cryptocurrencies and are using them to great success both for investment purposes and for direct business uses as well,” Nathan Wenzler, chief security strategist at AsTech, told Infosecurity. “These advocates are becoming more reliant on cryptocurrencies and typically support their use as being an inevitable trend that will only become more heavily adopted as time goes on. However, there are those that claim it's too risky and too volatile, and should the cryptocurrency market collapse, the government of South Korea would have to pick up the slack for the economic damage that would cause.”
There’s another dimension as well, according to Joseph Carson, chief security scientist at Thycotic, a Washington, D.C., based provider of privileged account management (PAM) solutions, having to do with cryptocurrency mining and taxation.
“China announcing they are going to clamp down on bitcoin mining…impacts China’s energy consumption and we could see a ripple effect around the world,” he said via email. “With the end of many countries’ tax years looming, the expectation is that many will dump Bitcoin to ensure they do not get hit with a huge capital gains tax bill. This could be seen as the wall at the end of the tunnel.”
He added, “I’m sure South Korea does not want to see their economy crash and significant GDP wiped overnight in value. The world is watching with huge anticipation.”
Then there are the cybersecurity concerns: For one thing, illicit mining of cryptocurrency by cybercriminals is skyrocketing and is responsible in many ways for the exploding value of currencies like Monero. Also, hacks on exchanges are not infrequent. In July, personal details on 30,000 people were stolen from South Korea-based crypto-currency exchange Bithumb, leading to the theft of funds from their Bitcoin and Ethereum accounts. The company, one of the largest exchanges for virtual currencies in the world, said the data theft happened after an employee's PC was hacked. From there, the hackers used the information to text and call users to con them out of their authentication codes, which were then used to steal funds from the accounts.
Another South Korean Bitcoin exchange, YoBit, was forced to close in December after suffering two major cyber-attacks in one year. It claimed it was “very sorry” but filed for bankruptcy after it suffered the December attack, less than eight months after the first.
In any event, South Korea has much to consider.
“By entertaining the notion of a ban on cryptocurrency trading, South Korea is evaluating whether or not the government can successfully manage the risk of what would happen if those cryptocurrencies collapsed while also promoting what they state is less immoral behaviors due to their view that cryptocurrency trading is akin to gambling and may lead to even worse offenses,” said Wenzler. “This ban, though, would impact a growing number of citizens and could cause a huge backlash against the government, both immediately and in any voting situation. At this point, it may be too early to guess at what a ban on cryptocurrency trading would do to South Korea, either economically or politically, but as the number of South Koreans who use cryptocurrencies increases, this issue will become more challenging to address at a national level.”
Source: info-security
Reddit Users Lose Bitcoin Tips After Third-Party Breach
Reddit has confirmed that one of its email providers, Mailgun, has been breached, resulting in the hacks of user profiles and their linked cryptocurrency accounts.
Attackers infiltrated Reddit accounts using password reset emails sent via the third-party vendor. Several Redditors also reported that their Bitcoin Cash tip accounts had been emptied out.
Despite the alarming details, Reddit urged the public to maintain perspective, noting that the attackers “did not have access to either Reddit’s systems or to a Redditor’s email account,” adding that the number of confirmed impacted users is less than 20 so far.
“On 12/31, Reddit received several reports regarding password reset emails that were initiated and completed without the account owners’ requests,” Reddit explained in a post. “We have been working to investigate the issue and coordinating with Mailgun, a third-party vendor we’ve been using to send some of our account emails including password reset emails,” it continued. “A malicious actor targeted Mailgun and gained access to Reddit’s password reset emails….We know this is frustrating as a user, and we have put additional controls in place to help make sure it doesn’t happen again.”
Mailgun, for its part, said that it has identified the attack vector—an employee’s compromised email account—and has patched the issue.
“On January 3, 2018, Mailgun became aware of an incident in which a customer’s API key was compromised and immediately began diagnostics to help determine the cause and the scope of impact,” Mailgun CTO Josh Odom wrote in a post. “We immediately closed the point of access to the unauthorized user and deployed additional technical safeguards to further protect this sensitive portion of our application.”
He added that the attack affected less than 1% of Mailgun’s entire customer base.
Source:
Info-Security
Intel Tiger Lake CPUs to come with Anti-Malware Protection
Intel’s Tiger Lake CPUs will come with Control-flow Enforcement Technology (CET), aimed at battling common control-flow hijacking attacks. I...
-
Last April, Steven Schoen received an email from someone named Natalie Andrea who said she worked for a company called We Purchase Apps. She...
-
By Carl Herberger This is Part 2 of our series on the top 5 most dangerous DDoS attacks and how you can successfully mitigate them. ATTAC...
-
French security researcher Bekanow discovered probably the biggest spambot in the whole spam history. Known as Onliner malware, the spambot ...