HardwareNews

Aldylkuzz, the ransomware in the shadow of WannaCry that undermines Monero without you noticing

The WannaCry ransomware has won the fame, but not the wool, who is taking the wool is the Adylkuzz ransomware, a ransomware that mines Monero on infected computers without the user being aware of this fact.

After the case of the infection appeared in Telefónica, we quickly began to follow the case and see what was happening, as the hours passed we learned more data and now we know who the culprit was, the WannaCry ransomware and that it had a Kill- switch that prevented infection. This ransomware is based on the EternalBlue security hole that should have been fixed by Microsoft. According to the cybersecurity firm ProofPoint, there is another malware that is using the Windows vulnerability to do something different, make the infected machine mine Monero. This ransomware has been named Aldylkuzz.

This botnet has been called Adylkuzz and is based on the execution of a CryptoNight algorithm that runs on the computer without the user's authorization and even without the user noticing it with the naked eye. This algorithm can be used to mine various cryptocurrencies in a simpler way than mining Bitcoin, the hackers behind the malware, according to the information security company, are opting to mine Monero. This is very interesting, since one of its most important characteristics is the opacity of its blockchain, something that allows hiding funds in a fairly simple way.

This discovery has been made while some experts were using machines in the laboratory, which were vulnerable to EternalBlue attacks, the basis of WannaCry and which makes use of the Windows security hole that was solved in March of last year. The researchers were surprised when they were not infected with WannaCry, but with Adylkuzz, which originates from private servers that have been scanning the network for vulnerable machines.

Monero

Another element of dangerous malware stolen from the NSA has also been discovered, such as DoublePulsar, which after exploiting the EternalBlue breach, installs the miner. The funny thing is that the malware patches the vulnerability of Windows, preventing the entry of other malware, such as WannaCry and thus ruining the party.

The symptoms are not nearly as obvious as in the case of the well-known ransomware and it is for this reason that ProofPoint considers it even more dangerous. The victims simply detect a slowness in the system and that they cannot access shared resources on the computer. Something alarming is that this malware does not have fewer days to live than WannaCry, but more, since it could have its origin before WannaCry, specifically it is speculated that it would have its origin on April 24. This infection wants nothing from us, only to mine Monero and could accumulate Altcoins worth more than a million dollars, a figure much higher than that obtained by WannaCry (which is a laugh compared to other ransomware).

[quote bcolor=»#dd3333″]Like the WannaCry campaign last week, this attack makes use of hacking tools stolen from the NSA and takes advantage of an already patched vulnerability in the Microsoft Windows network (…) For organizations that are using older versions of Windows that have not implemented the SMB (Server Message Block, where the vulnerability lies) patch released last month, their PCs and servers will remain vulnerable to this type of attack (…) Two major campaigns have already employed the hacking tools and the vulnerability; we expect more to follow and we recommend that organizations and individuals patch their machines as soon as possible. Note from ProofPoint[/quote]

Source: ProofPoint

Show more

Robert Sole

Director of Contents and Writing of this same website, technician in renewable energy generation systems and low voltage electrical technician. I work in front of a PC, in my free time I am in front of a PC and when I leave the house I am glued to the screen of my smartphone. Every morning when I wake up I walk across the Stargate to make some coffee and start watching YouTube videos. I once saw a dragon ... or was it a Dragonite?

Leave your comment

Your email address will not be published. Required fields are marked with *

Button back to top
CLOSE

Ad blocker detected

This site is funded through the use of advertising. We always make sure that the advertising is not too intrusive for the reader and we prioritize the reader's experience on the website. However, if you block the ads, part of our funding will be reduced.