Security researchers discover malware that infected 90,000 computers worldwide

Agencies
October 8, 2019

Security researchers have discovered that the Smominru malware infected 90,000 machines worldwide during the month of August, with an infection rate of up to 4,700 computers per day.

In its post-infection phase, it steals victim credentials, installs a Trojan module and a cryptominer and propagates inside the network, according to researchers from Guardicore, a data centre and cloud security company.

The botnet uses several methods to propagate, but primarily it infects a system in one of two ways -- either by brute-forcing weak credentials for different Windows services, or more commonly by relying on the infamous EternalBlue exploit, cybersecurity firm Kaspersky said in a blog post last week.

Even though Microsoft patched the vulnerability EternalBlue exploits, which made the WannaCry and NotPetya outbreaks possible, many companies are simply ignoring updates, Kaspersky said.

China, Taiwan, Russia, Brazil and the US have seen the most attacks, but that doesn't mean other countries are out of its scope. For example, the largest network Smominru targeted was in Italy, with 65 hosts infected.

The criminals involved are not too particular about their targets, which range from universities to healthcare providers.

However, one detail is very consistent. About 85 per cent of infections occur on Windows 7 and Windows Server 2008 systems. The rest include Windows Server 2012, Windows XP and Windows Server 2003.

After compromising the system, Smominru creates a new user, called admin$, with admin privileges on the system and starts to download a whole bunch of malicious payloads.

The most obvious objective is to silently use infected computers for mining cryptocurrency (namely, Monero) at the victim's expense.

The malware also downloads a set of modules used for spying, data exfiltration, and credential theft.

On top of that, once Smominru gains a foothold, it tries to propagate further within the network to infect as many systems as possible.

To protect their network, computers, and data from Smominru, users need to update operating systems and other software regularly, Kaspersky said.

It is also important for users to use strong passwords. A reliable password manager that helps you create, manage, and automatically retrieve and enter passwords may help protect you against brute-force attacks.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
July 28,2020

Bengaluru, Jul 28: Congress leader Siddaramaiah on Monday alleged that BJP is trying to destabilise the Congress government in Rajasthan.

"It is the duty of the Governor to act according to the decision of the state cabinet. But he is acting like a central government puppet," he said at a protest organised here by Karnataka Pradesh Congress Committee (KPCC).

He said the Congress is protesting across the country to save democracy and save the constitution.

"We are not fighting through violence. We are protesting peacefully. The Constitution has given the right to protest in a democratic system," he said.

He accused the BJP of "being disrespectful" to the Constitution.

"Governments must walk within the framework of the Constitution. The Constitution gives everyone rights and duties. BJP destabilises elected governments and buys our legislators by horse-trading by spending crores of money. The same thing happened in Karnataka as well," he alleged.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
March 18,2020

San Francisco, Mar 18: Facebook said a bug in its anti-spam system temporarily blocked the publication of links to news stories about the coronavirus. Guy Rosen, Facebook's vice president of integrity, said on Twitter Tuesday that the company was working on a fix for the problem.

Users complained that links to news stories about school closings and other information related to the virus outbreak were blocked by the company's automated system.

Later on Tuesday, Rosen tweeted that Facebook had restored all the incorrectly deleted posts, which also covered topics beyond the coronavirus.

Rosen said the problems were unrelated to any changes in Facebook's content-moderator workforce. The company reportedly sent its human moderators home this week because of the coronavirus outbreak.

A representative for Facebook did not immediately respond to questions on the status of Facebook's content moderators, many of whom do not work directly for the company and are not always able to work from home.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
March 25,2020

In an unprecedented crisis despite Prime Minister Narendra Modi assuring the continuation of essential services like food and groceries, online marketplaces like Flipkart and Amazon along with delivery platforms like Bigbasket, Grofers and FreshToHomes hit a major blockade on Wednesday as local authorities shut warehouses and sent delivery boys back, even harassed them.

Millions of people across cities were left helpless at homes as essential items like fruits and vegetables, dairy and milk, meat and fish etc did not reach their doors despite placing orders well in advance. Later, the orders went dry.

While Grofers' warehouse in Faridabad was closed by the local law enforcement agencies, Bigbasket complained that the police stopped its delivery partners and "some of them were even beaten up by for no fault of theirs".

"We are not operational due to restrictions imposed by local authorities on movement of goods in spite of clear guidelines provided by central authorities to enable essential services. We are working with the authorities to be back soon,' Bigbasket tweeted.

In a statement to IANS, Bigbasket said that it will help to have better coordination between the Centre and state, and between the state and local police to "ensure that our delivery vans and bikes don't get stopped by the police. Bigbasket and bb daily are not taking new orders".

Furious people stormed the social media platforms, writing their plight to NITI Aayog CEO Amitabh Kant on Twitter.

"Sir, all e-commerce are down. Believe me I tried everything (Grofers, Bigbasket, Flipkart, Amazon, Big Bazaar), no delivery till 31st March or Server Down or No Service. Need to think how we can enable them through digital India," tweeted one user.

Kant tweeted back to Bigbasket: "They should give me specifics - State & location. I will act on it by getting in touch with concerned authorities & sorting it out. Govt guidelines exempt them. We will ensure that citizens are not impacted".

Kant also responded to Grofers: "Cold storages & Warehouses as well as delivery of all essentials goods including food, pharma thru E-Commerce are exempted under MHA order. I have spoken to CS & DGP, Haryana . They have taken immediate action to ensure that supply chains efficiently function for the citizens".

The subscription-based hyperlocal delivery startup FreshToHome sent messages to its customers, saying that despite the government declaring food delivery as essential, "we are facing hardships in continuing our operations".

"Please bear with us as we are working hard to unblock local authority hurdles," said the FreshToHome team.

Reports later surfaced that the Department for Promotion of Industry and Internal Trade (DPIIT) has initiated talks with the state Chief Secretaries asking them not to restrict movement of people engaged in home delivery of essential items, mentioned in the list of exempted items circulated by the Home Ministry.

Meanwhile, Flipkart said it has temporarily suspended its operations and services - including grocery items. The marketplace has decided to halt all orders from March 25 for all three supply chains -- groceries, non-large goods and large items.

"Flipkart has temporarily suspended orders as we assess the possibilities of operating in the lockdown. We are prioritising the safety of our delivery executives and seeking the support of the local governments and police authorities to meet the needs of our customers as they stay home during this lockdown," Rajneesh Kumar, Chief Corporate Affairs Officer, Flipkart, said in a statement.

E-commerce giant Amazon said the company has to "temporarily stop taking orders and disable shipments for lower-priority products.

"For all pending customer orders on lower-priority products, we are reaching out to customers and giving them a choice to cancel their orders, and receive a refund for prepaid items," said the company.

Witnessing a surge in demand, supermarket chain Biz Bazaar entered the fray, with launching doorstep delivery services in major cities like Delhi, Mumbai, Bengaluru and Gurugram.

However, within no time, Big Bazaar was flooded with calls, forcing the company to issue a statement, saying that "In light of the recent announcement, we are receiving an unprecedented number of requests for doorstep delivery. There could be a delay due to the restrictions on movements".

Already battling massive surge in demand, the online delivery platforms faced other issues too, including zero access to several high-rises across the country which have gone under complete lockdown with all entry and exit gates locked.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.