Malware, Threat Intelligence, Network Security

Infostealers, cryptominers deployed in massive ISP exploitation campaign

System hacked warning alert on laptop computer. Cyber attack on computer network, virus, spyware, malware or malicious software. Cyber security and cybercrime concept. System security technology (3)

U.S. West Coast- and China-based internet service providers had more than 4,000 of their IP addresses subjected to an extensive brute-force attack campaign spreading information-stealing malware and cryptocurrency mining payloads, The Hacker News reports.

After achieving initial compromise through the abuse of weak credentials, attackers leveraging Eastern Europe-linked IP addresses performed network scanning and deactivated threat detection systems before proceeding with infostealer and XMRig cryptominer deployment, an investigation from the Splunk Threat Research Team revealed.

Such an infostealer not only obtained screenshots but also compromised clipboard-stored Bitcoin, Binance Chain BEP2, Ethereum, Litecoin, and TRON wallet addresses, which were eventually sent to a Telegram bot.

Additional findings showed impacted devices to be injected with a binary that facilitated the execution of the Auto.exe file for brute-force intrusions and the Masscan.exe multi masscan tool.

"This actor also moves and pivots primarily by using tools that depend and run on scripting languages (e.g., Python and Powershell), allowing the actor to perform under restricted environments and use API calls (e.g., Telegram) for [command-and-control] operations," said researchers.

An In-Depth Guide to Network Security

Get essential knowledge and practical strategies to fortify your network security.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds