Security researchers discover malware that infected 90,000 computers worldwide

Agencies
October 8, 2019

Security researchers have discovered that the Smominru malware infected 90,000 machines worldwide during the month of August, with an infection rate of up to 4,700 computers per day.

In its post-infection phase, it steals victim credentials, installs a Trojan module and a cryptominer and propagates inside the network, according to researchers from Guardicore, a data centre and cloud security company.

The botnet uses several methods to propagate, but primarily it infects a system in one of two ways -- either by brute-forcing weak credentials for different Windows services, or more commonly by relying on the infamous EternalBlue exploit, cybersecurity firm Kaspersky said in a blog post last week.

Even though Microsoft patched the vulnerability EternalBlue exploits, which made the WannaCry and NotPetya outbreaks possible, many companies are simply ignoring updates, Kaspersky said.

China, Taiwan, Russia, Brazil and the US have seen the most attacks, but that doesn't mean other countries are out of its scope. For example, the largest network Smominru targeted was in Italy, with 65 hosts infected.

The criminals involved are not too particular about their targets, which range from universities to healthcare providers.

However, one detail is very consistent. About 85 per cent of infections occur on Windows 7 and Windows Server 2008 systems. The rest include Windows Server 2012, Windows XP and Windows Server 2003.

After compromising the system, Smominru creates a new user, called admin$, with admin privileges on the system and starts to download a whole bunch of malicious payloads.

The most obvious objective is to silently use infected computers for mining cryptocurrency (namely, Monero) at the victim's expense.

The malware also downloads a set of modules used for spying, data exfiltration, and credential theft.

On top of that, once Smominru gains a foothold, it tries to propagate further within the network to infect as many systems as possible.

To protect their network, computers, and data from Smominru, users need to update operating systems and other software regularly, Kaspersky said.

It is also important for users to use strong passwords. A reliable password manager that helps you create, manage, and automatically retrieve and enter passwords may help protect you against brute-force attacks.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
July 28,2020

Bengaluru, Jul 28: Congress leader Siddaramaiah on Monday alleged that BJP is trying to destabilise the Congress government in Rajasthan.

"It is the duty of the Governor to act according to the decision of the state cabinet. But he is acting like a central government puppet," he said at a protest organised here by Karnataka Pradesh Congress Committee (KPCC).

He said the Congress is protesting across the country to save democracy and save the constitution.

"We are not fighting through violence. We are protesting peacefully. The Constitution has given the right to protest in a democratic system," he said.

He accused the BJP of "being disrespectful" to the Constitution.

"Governments must walk within the framework of the Constitution. The Constitution gives everyone rights and duties. BJP destabilises elected governments and buys our legislators by horse-trading by spending crores of money. The same thing happened in Karnataka as well," he alleged.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
May 22,2020

Kochi, May 22: During the nationwide COVID-19 lockdown, Kerala recorded the highest number of cyber attacks followed by Punjab and Tamil Nadu, a study by anti-virus software firm K7 Computing said on Thursday.

In a statement issued in Chennai, the company said its K7 Computing's Cyber Threat Report, a comprehensive analysis of cyber attacks during the lockdown has found that Kerala recorded the highest number of cyber attacks during this period. The report analyses various cyber attacks within India during the pandemic and reveals that threat actors targeted the state with COVID-themed attacks aimed at exploiting user trust.

In Kerala, regions like Kottayam, Kannur, Kollam, and Kochi saw the highest hits with 462, 374, 236, and 147 attacks respectively, while the state as a whole saw around 2,000 attacks during the period - the highest thus far in the country.

This was followed by Punjab with 207 attacks and Tamil Nadu with 184 attacks, the company said.

The sudden surge in the frequency of attacks witnessed from February 2020 to mid-April 2020 indicates that scamsters across the world were exploiting the widespread panic around coronavirus at both the individual and corporate level.

These attacks aimed to compromise computers and mobile devices to gain access to users' confidential data, banking details, and cryptocurrency accounts.

The key threats seen during this period ranged from phishing attacks to rogue apps disguised as COVID-19 information apps that targeted users' sensitive data. Phishing attacks were noticed more in Tier-II and Tier-III cities while the metros fared better. Smaller cities saw over 250 attacks being blocked per 10,000 users.

Users from Ghaziabad and Lucknow seem to have faced almost 6 and 4 times the number of attacks as Bengaluru users.

According to the statement, a majority of the recorded attacks were phishing attacks with sophisticated campaigns that could easily snare even the most educated users. These attacks were aimed at heightening users' fears and creating a sense of urgency to take action.

K7 Labs noticed phishing attacks where scamsters posed as representatives of the United States Department of Treasury, the World Health Organization (WHO), and the Centres for Disease Control and Prevention (CDC), the company said.

Users were encouraged to visit links that would automatically download malware on the host computer such as the Agent Tesla keylogger or Lokibot information-stealing malware, infamous banking Trojans such as Trickbot or Zeus Sphinx, and even disastrous ransomware.

Other attacks included infected COVID-19 Android apps like CoronaSafetyMask that scam users with promises of masks for an upfront payment; the spyware app Project Spy; and seemingly genuine apps that are infected with dangerous malware like banking Trojans such as Ginp, Anubis and Cerberus.

"Covid-19 has created an ideal situation for various threat actors to target individuals and enterprises alike. The panic caused by the stringent lockdown measures and rapid spread of this virus has left many people looking for more information on the situation," J. Kesavardhanan, Founder and CEO of K7 Computing was quoted as saying in the statement.

"Threat actors exploit this fear to their advantage and scam users into downloading malicious software and divulging sensitive information like banking codes. The need to be cyber cautious has never been greater. This is more so in the case of corporates who have adopted a work from home policy hurriedly without adequate cyber hygiene. We have seen an increase in attacks on enterprises and SME employees as well," he added.

Such attacks are expected to continue till normalcy returns. Social engineering attacks targeted at winning users' trust will gain momentum.

Healthcare institutions, well-known government offices, and international organisations will continue to be a prime target throughout the pandemic, the statement said.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
February 5,2020

Feb 5: Tesla is making Elon Musk a lot richer without paying him a dime.

A blistering stock rally has bolstered the value of CEO Musk's 19% stake in the electric car maker by $16 billion since the start of 2020, to $30 billion.

Tuesday's steep climb in the share price could sweeten Musk's payday under his record-breaking compensation package, which is built on stock options that rely on market value targets. Two milestones have now been achieved that could see Musk unlock options worth $1.8 billion.

The controversial chief executive, who is also the majority owner and CEO of rocket maker SpaceX, recently testified that he did not have a lot of cash as he successfully defended himself in a defamation lawsuit. He previously has taken loans using his Tesla shares as collateral.

Musk does not take a salary, choosing instead a risky options package that envisions the stock market value of Tesla rising to $650 billion over 10 years, a prospect that was derided by some investors when the deal was announced in 2018.

That target now looks less crazy. Shares of Tesla have rallied over 50% since the company posted its second consecutive quarterly profit last Wednesday, which was viewed as a major accomplishment for a company competing against established automotive heavyweights including General Motors Co  and BMW.

Tesla shares have climbed about 400% since early June, helped by the company's better-than-expected financial results and ramped-up production at its new car factory in Shanghai.

On Tuesday, Tesla surged as much as 24% before falling back in the final minutes of the trading session to end the day up 13.7%. That put its market capitalization at $160 billion, almost twice the combined value of Ford Motor and General Motors.

The shares had also rallied on Monday, partly fueled by Panasonic Corp's 6752.T saying its automotive battery venture with Tesla was profitable for the first time.

The options Musk was awarded in 2018 vest incrementally based on targets for Tesla's stock market value and its financial performance. The market capitalization would have to sustainably rise by $50 billion increments over the agreement's 10-year period, with the full package payout reached if the market cap reaches $650 billion, as well as the company's meeting revenue and profit targets.

Musk is on his way to seeing his first two tranches of options vest. He achieved operational targets on revenue and adjusted earnings last year.

The rise in Tesla's market capitalization last month to a target of $100 billion opened the way for Musk's first tranche of options to vest. With Tuesday's surging share price, the market capitalization blew past the second target of $150 billion, opening the way for the second tranche to vest. Tesla's market capitalization must stay at or above each target level for one- and six-month averages for each set of options to vest.

Tesla was valued at about $52 billion when shareholders approved the pay package in March 2018, a time when the company faced a cash crunch, production delays and increasing competition from rivals.

A full payoff for Musk would surpass anything previously granted to U.S. executives, according to Institutional Shareholder Services, a proxy advisor that recommended investors reject the pay package deal at the time.

Musk currently owns about 34 million Tesla shares, and his compensation package would let him buy another 20.3 million shares if all his options tranches vest.

When Tesla unveiled Musk’s package, it said he could in theory reap as much as $55.8 billion if no new shares were issued. However, Tesla has since awarded stock to employees and last year sold $2.7 billion in shares and convertible bonds, diluting the value of the stock.

Musk has transformed Tesla from a niche car maker with production problems into the global leader in electric vehicles, with U.S. and Chinese factories. So far it has stayed ahead of more established rivals including BMW and Volkswagen.

Many investors remain skeptical that Tesla can consistently deliver profit, cash flow and growth. More Wall Street analysts rate Tesla "sell" than "buy," and the company's stock is the most shorted on Wall Street.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.