Menu

The PhotoMiner Campaign
📰
0

The PhotoMiner Campaign

Akamai·Daniel Goldberg·about 1 month ago
#1u5YJ1Sy
Reading 0:00
15s threshold

Over the past few months, we’ve been following a new type of worm we named  PhotoMiner . PhotoMiner features a unique infection mechanism, reaching endpoints by infecting websites hosted on FTP servers while making money by mining  Monero . The choice of a lesser known currency with a good exchange rate allows the attackers to rapidly gain money while the sophisticated use of safeguards makes it resilient to most disruption attempts, potentially leaving victims infected for years. \r\nWe’ve documented thousands of attacks originating from hundreds of IPs, running similar attack flows while using different binaries. In this report we will share our research on the PhotoMiner’s timelines, infection strategies, C&C servers and provide tools to help detect the malware. \r\n Attack description \r\n On January 10 2016, Guardicore Global Sensor Network detected an automated attack uploading suspicious files to FTP hosts.…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More