|

New Linux mining malware uncovered

  • A rootkit is being used by Skidmap to hide its cryptocurrency mining activities.
  • Cryptojacking campaigns and ransomware attacks have increased by 29% in Q1 2019.

Augusto Remillano II and Jakub Urbanec recently announced in a Trend Micro post that they have come across new Linux malware. The analysts reported in the security intelligence blog that the malware loads malicious kernel modules to hide its cryptocurrency mining operations.

According to the analysts, a rootkit is being used by Skidmap to hide its cryptocurrency mining activities. It is a program that installs and executes code on a system without end-user consent or knowledge. This makes its malware components undetectable by the infected system’s monitoring tools. Apart from conducting a cryptojacking campaign, the malware reportedly provides attackers with “unfettered access” to the affected system. The analysts said: 

“Skidmap also sets up a way to gain backdoor access to the machine and also replaces the system’s pam_unix.so file with its own malicious version. This malicious file accepts a specific password for any users, thus allowing the attackers to log in as any user in the machine.”

Cryptojacking is an industry term given to crypto-mining attacks that are carried out by installing malware to infect a computer. The malware is used to acquire access to a computer’s processing power for mining cryptocurrencies without letting the owner know. McAfee Labs, a cybersecurity company, released a threat report in August. The company pointed out a rise in cryptojacking campaigns and ransomware attacks in Q1 2019. According to the report, cryptojacking campaigns have increased by 29%.  

Author

Rajarshi Mitra

Rajarshi Mitra

Independent Analyst

Rajarshi entered the blockchain space in 2016. He is a blockchain researcher who has worked for Blockgeeks and has done research work for several ICOs. He gets regularly invited to give talks on the blockchain technology and cryptocurrencies.

More from Rajarshi Mitra
Share:

Editor's Picks

Crypto Today: Bitcoin, Ethereum, XRP trade under sustained selling pressure despite mild ETF inflows

Cryptocurrency prices remain under pressure as a risk-off mood persists on Friday, with Bitcoin consolidating its losses above $62,000. Altcoins, including Ethereum and Ripple, are extending their weakness, trading near lower support levels around $1,600 and $1.12, respectively.

Bitcoin Weekly Forecast: After the bloodbath, everyone looks at $60,000

Bitcoin (BTC) hovers above $62,000 at the time of writing on Friday, weighed down by growing risk-off sentiment due to persistent geopolitical tensions in the Middle East and sticky macroeconomic uncertainty.

Cardano hits five-year low even as Hoskinson clarifies "break" isn't an exit

Cardano price is down 10% at press time on Friday, extending losses over 30% so far this week amid Charles Hoskinson's clarification that "break" isn't an exit. A reactionary spike in on-chain activity and social chatter, reflecting a strength of community, but fails to absorb the price decline.

Arthur Hayes' “Holy Trinity” is dead: Exits Zcash after Orchard Pool exploit

Arthur Hayes dumped his entire Zcash holdings on Friday, a day after selling his HYPE and NEAR holdings. Zcash is down 13% so far on Friday, extending the 26% drop from the previous day.

Bitcoin: After the bloodbath, everyone looks at $60,000
Bitcoin (BTC) hovers above $62,000 at the time of writing on Friday, weighed down by growing risk-off sentiment due to persistent geopolitical tensions in the Middle East and sticky macroeconomic uncertainty. The institutional sell-off continued to wreak havoc on capital flows, with spot Bitcoin Exchange-Traded Funds (ETFs) recording billions in outflows.