Experts believe it is developing a botnet, and operators have recently added scanning capabilities to search for vulnerable JBoss servers (leveraging CVE-2017-12149).
It is estimated that by the end of December, the PyCryptoMiner botnet has generated approximately $ 46,000 in revenue.
Experts say the PyCryptoMiner botnet is shunned because of its scripting-based nature because it’s executed by legitimate binaries and so hard to detect.
Malware spreads by trying to guess the SSH login credentials of the target Linux system. Once the SSH credentials have been guessed, the bot will deploy a simple base64-encoded Python script for connecting to the C & C server to download and execute additional Python code.
Security experts at F5 discovered a new Linux Monero crypto-miner botnet dubbed PyCryptoMiner spreading over the SSH protocol. F5 researchers discovered a new Linux crypto-miner botnet dubbed PyCryptoMiner spreading over the SSH protocol. The Monero miner botnet is based on the Python scripting language, it leverages Pastebin as command and control server infrastructure when the original C&C isn’t available. If all C&C servers Engaging post, Read More…
thumbnail courtesy of securityaffairs.co
The original curated post is from Safe Harbor on Cyber.com gbhackers.com
PyCryptoMiner – A New Linux Crypto-miner Botnet Spreading over the SSH Protocol to Mining Monero
Highly Sophisticated Python Script Based Linux Crypto-miner botnet called PyCryptoMiner abusing SSH port and targeting Linux users to mining Monero CryptoCurrency. Its written in python language which is difficult to detect and this botnet crypto-miner uses over 36,000 domains that is related to scams, gambling, and adult services. This Crypto miner mainly focusing on mining Monero and… PyCryptoMiner – A New Linux Crypto-miner Botnet Spreading over the SSH Protocol to Mining Monero
If you like to receive more of these curated news alerts then subscribe to my mailing list. and come back soon at https://www.safeharboroncyber.com/Blog/ to read further CyberWisdom Commentaries