Site navigation

New Stealth Malware Hijacks Computers to Generate Cash for Criminals

Staff Writer

,

mining for cryptocurrency

A crypto-mining malware that utilises anti-detection techniques has been discovered by Trend Micro researchers.

A new cryptocurrency-mining malware that uses evasion techniques, including Windows Installer, as part of its routine, has been discovered.

Trend Micro researchers found that the cryptocurrency miner, identified as Coinminer.Win32.MALXMR.TIAOODAM, uses multiple obfuscations and packing routines.

The malware utilises the Windows platform and, despite it being graded as having an overall ‘low risk’, its damage potential was rated in the ‘medium’ range.

Avoiding detection

Mining for cryptocurrency can very be lucrative but the process is resource-intensive. This is the primary reason why malicious actors continue to find ways to exploit other machines using malware, the researchers noted. This particular malware is largely successful in avoiding detection, especially when combined with obfuscation routines, they explained.

The coinminer is said to infect the user system after arriving as a Windows Installer MSI file via internet download or having been added to the machine by other malware. The researchers explained that it drops multiple files in the directory as part of its process and uses the CryptoNight algorithm for its coin-mining routing.

The files include a .bat file that paralyses any anti-malware software operating on the machine, a .exe unzipping tool and a password-protected zip file in the guise of an icon (.ico) file.

Another two files were revealed after the icon.ico was unpacked before the next part of the installation process began creating copies of the kernel file and a Windows USER component. The installation uses Cyrillic text, rather than English, though it is unknown where in the world was created.

A statement from the Trend Micro researchers read: “To make detection and analysis even more difficult, the malware also comes with a self-destruct mechanism.

“It deletes every file under its installation directory and removes any trace of installation in the system. One notable aspect of the malware is that it uses the popular custom Windows Installer builder WiX as a packer, most likely as an additional anti-detection layer.

“This indicates that the threat actors behind it are exerting extra effort to ensure that their creation remains as stealthy as possible.”

DIGIT Staff Writer Robot

Staff Writer

Staff Writer - DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data