{"id":181063,"date":"2023-09-07T21:39:26","date_gmt":"2023-09-07T21:39:26","guid":{"rendered":"https:\/\/precoinnews.com\/?p=181063"},"modified":"2023-09-07T21:39:26","modified_gmt":"2023-09-07T21:39:26","slug":"windows-tool-targeted-by-hackers-deploys-crypto-mining-malware","status":"publish","type":"post","link":"https:\/\/precoinnews.com\/crypto\/windows-tool-targeted-by-hackers-deploys-crypto-mining-malware\/","title":{"rendered":"Windows tool targeted by hackers deploys crypto mining malware"},"content":{"rendered":"

Hackers have been using a Windows tool to drop cryptocurrency-mining malware since November 2021,\u00a0according to an analysis from Cisco’s Talos Intelligence. The attacker exploits Windows Advanced Installer \u2014 an application that helps developers package other software installers, such as Adobe Illustrator \u2014 to execute malicious scripts on infected machines.\u00a0<\/p>\n

According to a Sept. 7 blog post, the software installers affected by the attack are mainly used for 3D modeling and graphic design. Additionally, most of the software installers used in the malware campaign are written in French. The findings suggest that the “victims are likely across business verticals, including architecture, engineering, construction, manufacturing, and entertainment in French language-dominant countries,” explains the analysis. <\/p>\n

The attacks predominantly affect users in France and Switzerland, with a few infections in other countries, including the United States, Canada, Algeria, Sweden, Germany, Tunisia, Madagascar, Singapore and Vietnam, the post notes based on DNS request data sent to the attacker\u2019s command and control (C2) host. <\/p>\n

The illicit crypto mining campaign identified by Talos involves the deployment of malicious PowerShell and Windows batch scripts to execute commands and establish a backdoor in the victim’s machine. PowerShell, specifically, is well-known for running in the memory of the system instead of the hard drive, making it harder to identify an attack. <\/p>\n

<\/p>\n

Once the backdoor is installed, the attacker executes additional threats, such as the Ethereum crypto-mining program PhoenixMiner, and lolMiner, a multi-coin mining threat.<\/p>\n

“These malicious scripts are executed using Advanced Installer\u2019s Custom Action feature, which allows users to predefine custom installation tasks. The final payloads are PhoenixMiner and lolMiner, publicly available miners relying on computers\u2019 GPU capabilities”<\/p><\/blockquote>\n

The use of crypto mining malware is known as cryptojacking, and involves installing a crypto mining code on a device without the user’s knowledge or permission in order to illegally mine cryptocurrencies. Signs that mining malware may be running in a machine include overheating and poorly performing devices.<\/p>\n

Using malware families to hijack devices to mine or steal cryptocurrencies isn’t a new practice. Former smartphone giant BlackBerry recently identified\u00a0malware scripts actively targeting at least three sectors, including financial services, healthcare and government.<\/p>\n

Magazine:<\/em><\/strong> \u2018Moral responsibility\u2019 \u2014 Can blockchain really improve trust in AI?<\/em><\/strong><\/p>\n

Source: Read Full Article<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"

Hackers have been using a Windows tool<\/p>\n","protected":false},"author":3,"featured_media":181062,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"yoast_head":"\nWindows tool targeted by hackers deploys crypto mining malware - Pre Coin News<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/precoinnews.com\/crypto\/windows-tool-targeted-by-hackers-deploys-crypto-mining-malware\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Windows tool targeted by hackers deploys crypto mining malware - Pre Coin News\" \/>\n<meta property=\"og:description\" content=\"Hackers have been using a Windows tool\" \/>\n<meta property=\"og:url\" content=\"https:\/\/precoinnews.com\/crypto\/windows-tool-targeted-by-hackers-deploys-crypto-mining-malware\/\" \/>\n<meta property=\"og:site_name\" content=\"Pre Coin News\" \/>\n<meta property=\"article:published_time\" content=\"2023-09-07T21:39:26+00:00\" \/>\n<meta name=\"author\" content=\"mediabest\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/precoinnews.com\/wp-content\/uploads\/2023\/09\/Windows-tool-targeted-by-hackers-deploys-crypto-mining-malware.jpg\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"mediabest\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/precoinnews.com\/crypto\/windows-tool-targeted-by-hackers-deploys-crypto-mining-malware\/\",\"url\":\"https:\/\/precoinnews.com\/crypto\/windows-tool-targeted-by-hackers-deploys-crypto-mining-malware\/\",\"name\":\"Windows tool targeted by hackers deploys crypto mining malware - Pre Coin News\",\"isPartOf\":{\"@id\":\"https:\/\/precoinnews.com\/#website\"},\"datePublished\":\"2023-09-07T21:39:26+00:00\",\"dateModified\":\"2023-09-07T21:39:26+00:00\",\"author\":{\"@id\":\"https:\/\/precoinnews.com\/#\/schema\/person\/ad0e9920e03d3b41c7ad02a18375d76a\"},\"breadcrumb\":{\"@id\":\"https:\/\/precoinnews.com\/crypto\/windows-tool-targeted-by-hackers-deploys-crypto-mining-malware\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/precoinnews.com\/crypto\/windows-tool-targeted-by-hackers-deploys-crypto-mining-malware\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/precoinnews.com\/crypto\/windows-tool-targeted-by-hackers-deploys-crypto-mining-malware\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/precoinnews.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Crypto\",\"item\":\"https:\/\/precoinnews.com\/category\/crypto\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Windows tool targeted by hackers deploys crypto mining malware\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/precoinnews.com\/#website\",\"url\":\"https:\/\/precoinnews.com\/\",\"name\":\"Pre Coin News\",\"description\":\"precoinnews.com\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/precoinnews.com\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/precoinnews.com\/#\/schema\/person\/ad0e9920e03d3b41c7ad02a18375d76a\",\"name\":\"mediabest\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/precoinnews.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/f5f13cb3b94fc348d515c0951f6ca073?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/f5f13cb3b94fc348d515c0951f6ca073?s=96&d=mm&r=g\",\"caption\":\"mediabest\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Windows tool targeted by hackers deploys crypto mining malware - Pre Coin News","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/precoinnews.com\/crypto\/windows-tool-targeted-by-hackers-deploys-crypto-mining-malware\/","og_locale":"en_US","og_type":"article","og_title":"Windows tool targeted by hackers deploys crypto mining malware - Pre Coin News","og_description":"Hackers have been using a Windows tool","og_url":"https:\/\/precoinnews.com\/crypto\/windows-tool-targeted-by-hackers-deploys-crypto-mining-malware\/","og_site_name":"Pre Coin News","article_published_time":"2023-09-07T21:39:26+00:00","author":"mediabest","twitter_card":"summary_large_image","twitter_image":"https:\/\/precoinnews.com\/wp-content\/uploads\/2023\/09\/Windows-tool-targeted-by-hackers-deploys-crypto-mining-malware.jpg","twitter_misc":{"Written by":"mediabest","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/precoinnews.com\/crypto\/windows-tool-targeted-by-hackers-deploys-crypto-mining-malware\/","url":"https:\/\/precoinnews.com\/crypto\/windows-tool-targeted-by-hackers-deploys-crypto-mining-malware\/","name":"Windows tool targeted by hackers deploys crypto mining malware - Pre Coin News","isPartOf":{"@id":"https:\/\/precoinnews.com\/#website"},"datePublished":"2023-09-07T21:39:26+00:00","dateModified":"2023-09-07T21:39:26+00:00","author":{"@id":"https:\/\/precoinnews.com\/#\/schema\/person\/ad0e9920e03d3b41c7ad02a18375d76a"},"breadcrumb":{"@id":"https:\/\/precoinnews.com\/crypto\/windows-tool-targeted-by-hackers-deploys-crypto-mining-malware\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/precoinnews.com\/crypto\/windows-tool-targeted-by-hackers-deploys-crypto-mining-malware\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/precoinnews.com\/crypto\/windows-tool-targeted-by-hackers-deploys-crypto-mining-malware\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/precoinnews.com\/"},{"@type":"ListItem","position":2,"name":"Crypto","item":"https:\/\/precoinnews.com\/category\/crypto\/"},{"@type":"ListItem","position":3,"name":"Windows tool targeted by hackers deploys crypto mining malware"}]},{"@type":"WebSite","@id":"https:\/\/precoinnews.com\/#website","url":"https:\/\/precoinnews.com\/","name":"Pre Coin News","description":"precoinnews.com","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/precoinnews.com\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/precoinnews.com\/#\/schema\/person\/ad0e9920e03d3b41c7ad02a18375d76a","name":"mediabest","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/precoinnews.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/f5f13cb3b94fc348d515c0951f6ca073?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f5f13cb3b94fc348d515c0951f6ca073?s=96&d=mm&r=g","caption":"mediabest"}}]}},"_links":{"self":[{"href":"https:\/\/precoinnews.com\/wp-json\/wp\/v2\/posts\/181063"}],"collection":[{"href":"https:\/\/precoinnews.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/precoinnews.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/precoinnews.com\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/precoinnews.com\/wp-json\/wp\/v2\/comments?post=181063"}],"version-history":[{"count":0,"href":"https:\/\/precoinnews.com\/wp-json\/wp\/v2\/posts\/181063\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/precoinnews.com\/wp-json\/wp\/v2\/media\/181062"}],"wp:attachment":[{"href":"https:\/\/precoinnews.com\/wp-json\/wp\/v2\/media?parent=181063"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/precoinnews.com\/wp-json\/wp\/v2\/categories?post=181063"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/precoinnews.com\/wp-json\/wp\/v2\/tags?post=181063"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}