80,000 computers around the world have been hijacked for mining: Disguise technology is extremely advanced, and they will be repeatedly installed

80,000 computers around the world have been hijacked for mining: Disguise technology is extremely advanced, and they will be repeatedly installed

Source: IT Home

Microsoft has published an alert detailing a new malware variant called Dexphot that has infected more than 80,000 devices since it was first discovered in 2018.

It is reported that hackers mainly use Dexphot to mine cryptocurrencies, not to steal data. Although the virus is relatively harmless, the methods used are very complex, allowing it to evade detection by traditional security tools. One of its techniques is polymorphic camouflage, which can constantly change its footprint on the computer, changing it every 20-30 minutes. It can also reinstall itself to ensure that there is enough time for mining.

Dexphot writes five key files to disk, including an installer with two URLs; an MSI package downloaded from one of the URLs as a password-protected zip file; a loader DRL extracted from the archive; and an encrypted data file where three additional executables are loaded into system processes.

"Besides the installer, other processes that run during execution are legitimate system processes. This can make detection and remediation more difficult," researchers noted. "In later stages, Dexphot targets several other system processes for hollowing, including svchost.exe, tracert.exe, and setup.exe."

Currently, Microsoft has deployed relevant strategies to improve detection rates and prevent attacks, and the number of infected devices has slowly decreased. As of July 31 this year, it has been less than 10,000.


<<:  Ant S9 has reached the shutdown price. It used to make 90 yuan a day, but now it makes 6 yuan.

>>:  New feature of F2Pool | ZEC smart mine jumping

Recommend

Men with moles on their earlobes

Ears are an important part of our body and withou...

Birthmark fortune telling diagram good or bad

Birthmarks are no longer unfamiliar to us. If you...

How did Xu Fu predict Zhou Yafu's fate by looking at his face?

During the Han Dynasty, the theories of Yin and Y...

What does a short-lived person look like? See if you are a short-lived person.

Everyone hopes to be healthy and live a long life...

Are you prone to bad luck in love according to your face?

Female friends often say that they have encounter...

Where to get moles and become rich in the future?

Becoming rich and powerful in the future is actua...

Free SMS service for virtual mobile numbers in 28 countries

As one of the most popular virtual mobile phone n...

Royal Bank of Canada may launch blockchain program next year

Dave戴夫•麦凯, president and CEO of Royal Bank of Can...

Bitcoin price crashes 3% after miners’ Bitcoin outflow hits 5-month high

The price of Bitcoin (BTC) fell from $10,580 to a...

Every step forward is a new feat | Review of Filecoin’s development history

2020 is a turbulent year, a year of both opportun...

What does it mean if a man has a mole on his eyebrow?

Every mole has its own meaning. So what does it m...

Why do people with thick eyelids have bad tempers?

Why do people with thick eyelids have bad tempers...

Blockchain Experts Telephone Conference Minutes

[ summary ] Report highlights Event description S...