Stories
Slash Boxes
Comments

SoylentNews is people

posted by Fnord666 on Wednesday March 07 2018, @06:27PM   Printer-friendly
from the miner-kerfluffle dept.

Cryptocurrency-mining malware-scum have started to write code that evicts rivals from compromised computers.

The miner in question was first noticed by SANS Internet Storm Center handler Xavier Mertens. Mertens spotted the PowerShell script on March 4, and noting that it kills any other CPU-greedy processes it spots on target machines, he wrote: “The fight for CPU cycles started!”

Pre-infection, the attack script checks whether a target machine is 32-bit or 64-bit and downloads files known to VirusTotal as hpdriver.exe or hpw64 (they're pretending to be HP drivers of some kind).

If successfully installed, the attack then lists running processes and kills any it doesn't like. Mertens noted that alongside ordinary Windows stuff, the list of death-marked processes includes many associated with cryptominers, some of which are listed below.

Mertens wrote that the script also checks for processes associated with security tools.


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 2) by requerdanos on Wednesday March 07 2018, @10:00PM

    by requerdanos (5997) Subscriber Badge on Wednesday March 07 2018, @10:00PM (#649194) Journal

    The only thing that can stop bad malware on a computer is good malware on a computer.

    This idea that there is "good" malware and "bad" malware is an excuse people use to run Windows [upgradefromwindows.com] in the first place.

    Starting Score:    1  point
    Karma-Bonus Modifier   +1  

    Total Score:   2