80,000 computers around the world have been hijacked for mining: Disguise technology is extremely advanced, and they will be repeatedly installed

80,000 computers around the world have been hijacked for mining: Disguise technology is extremely advanced, and they will be repeatedly installed

Source: IT Home

Microsoft has published an alert detailing a new malware variant called Dexphot that has infected more than 80,000 devices since it was first discovered in 2018.

It is reported that hackers mainly use Dexphot to mine cryptocurrencies, not to steal data. Although the virus is relatively harmless, the methods used are very complex, allowing it to evade detection by traditional security tools. One of its techniques is polymorphic camouflage, which can constantly change its footprint on the computer, changing it every 20-30 minutes. It can also reinstall itself to ensure that there is enough time for mining.

Dexphot writes five key files to disk, including an installer with two URLs; an MSI package downloaded from one of the URLs as a password-protected zip file; a loader DRL extracted from the archive; and an encrypted data file where three additional executables are loaded into system processes.

"Besides the installer, other processes that run during execution are legitimate system processes. This can make detection and remediation more difficult," researchers noted. "In later stages, Dexphot targets several other system processes for hollowing, including svchost.exe, tracert.exe, and setup.exe."

Currently, Microsoft has deployed relevant strategies to improve detection rates and prevent attacks, and the number of infected devices has slowly decreased. As of July 31 this year, it has been less than 10,000.


<<:  Ant S9 has reached the shutdown price. It used to make 90 yuan a day, but now it makes 6 yuan.

>>:  New feature of F2Pool | ZEC smart mine jumping

Recommend

How to explain whether a man with a mole on the sole of his foot is good or not

Moles are very common and can be found on various...

The first blockchain birth certificate was created

Roma Siri , the baby girl has her own unique node...

Is it good to have a mole on your foot?

For some people, moles are something that cannot ...

Health from the five facial features: mouth

Health from the five facial features: mouth In ph...

Analysis of the career lines of girls who start their own businesses

What does the career line diagram on a girl’s pal...

Blockchain for record keeping? UK government tries it out

The UK government is exploring the use of blockch...

Where is the brow bone?

The face is the most obvious part of our body, be...

The palmistry characteristics that are the worst for men

The palmistry characteristics that are the worst ...

Is it good for a man to have an overbite?

How to interpret a man's overbite? Under norm...

Magpie Eyes Physiognomy

Magpie Eyes Trust Characteristics of magpie eyes ...

What is the fortune of a person with a receding chin?

The chin is what we often call the ground chin in...

Is America ready for a cashless society? Poll gives you the answer

If you had watched Mark Dice's YouTube videos...