|

Cybersecurity firm finds similarity in Monero botnet and “Outlaw” attack

  • Outlaw, the hacking group, used “Haiduc” to attack a vulnerable system on the internet.
  • Presently, the hackers are spreading malware through a malicious URL.

TrendMicro’s Security Intelligence Blog has recently discovered a URL that circulates a Monero mining botnet which is almost identical to a similar botnet created by the Outlaw hacking group. TrendMicro states that though in its testing phase, the infection attempts have already been carried out in China. Hackers use the group’s primary hacking tool, dubbed “Haiduc,”(and the Romanian word for “outlaw”)which is a Perl-based shellbot that attack vulnerabilities in the Internet-of-Things.

Previously, the hacking group used to look for a vulnerable system on the internet to launch an attack. At present, it is reported that the malware is primarily being spread through a malicious URL which consists of a Monero-mining script as well as a backdoor-based exploit. 

Once Haiduc comes across a vulnerability, or the URL has been accessed, the botnet uses a brute force attack exploit which allows remote access to their victim’s systems. After the system is under the control of the hackers, the malware downloads the cryptocurrency miner payload. The malware also deletes the cryptocurrency mining software installed on the system, if any. 

The bot is also reportedly “capable of launching distributed denial-of-service (DDoS) attacks, allowing the cybercriminals to monetize their botnet through cryptocurrency mining and by offering DDoS-for-hire services.” DDoS attacks occur when multiple systems attempt to overwhelm the bandwidth of another targeted system. If the attack is successful, the system will be so overwhelmed that it will not be accessible to anyone besides the person launching the attack. DDoS attacks are quite prominent in the crypto sphere.

The RWTH Aachen University in Germany reported that this kind of involuntary crypto mining is known as “cryptojacking” which amounts to over $250,000 worth of cryptocurrency per month.
 

Author

Rajarshi Mitra

Rajarshi Mitra

Independent Analyst

Rajarshi entered the blockchain space in 2016. He is a blockchain researcher who has worked for Blockgeeks and has done research work for several ICOs. He gets regularly invited to give talks on the blockchain technology and cryptocurrencies.

More from Rajarshi Mitra
Share:

Editor's Picks

Starknet unveils strkBTC, shielded Bitcoin transactions on Ethereum Layer 2

Starknet, the Ethereum Layer 2 network developed by StarkWare, today announced strkBTC, a wrapped Bitcoin asset that introduces optional shielding while preserving full DeFi composability.

Bitcoin, Ethereum, and Ripple consolidate with short-term cautious bullish bias

Bitcoin, Ethereum and Ripple are consolidating near key technical areas on Friday, showing mild signs of stabilization after recent volatility. BTC holds above $67,000 despite mild losses so far this week, while ETH hovers around $2,000 after a rejection near its upper consolidation boundary.

Ethereum Price Forecast: FG Nexus continues distribution amid signs of returning risk-on sentiment

FG Nexus, once dubbed an Ethereum treasury firm, resumed offloading the top altcoin on Wednesday, distributing 7,550 ETH, according to data from smart money tracker EmberCN.

Top Crypto Gainers: Stable and Decred rally, Pippin approaches record highs

Altcoins, such as Stable, Decred, and Pippin, are extending gains so far this week, defying the risk-averse conditions in the broader cryptocurrency market. Stable and Pippin are near record high levels, while Decred extends its breakout rally above $30.

Bitcoin Price Annual Forecast: BTC holds long-term bullish structure heading into 2026

Bitcoin (BTC) is wrapping up 2025 as one of its most eventful years, defined by unprecedented institutional participation, major regulatory developments, and extreme price volatility.

Bitcoin: Another month of losses, and it’s been five

Bitcoin (BTC) price is stabilizing around $68,000 at the time of writing on Friday, but the Crypto King is poised to close February on a fragile footing, marking its fifth consecutive month of losses since October and a rare start to the year with back-to-back monthly corrections.