Close Menu
    Facebook X (Twitter) Instagram
    ESP Blockchain Journal
    • Noticias
      • Noticias Blockchain
      • Noticias Bitcoin
      • Noticias Ethereum
      • Noticias Ripple
      • NFT
      • Metaverso
      • DeFi
      • Noticias Tron
      • Noticias Litecoin
      • Noticias Monero
      • Noticias Cardano
      • Noticias Stellar
      • Noticias Algorand
      • Noticias Dogecoin
      • Noticias Polkadot
      • Noticias Kusama
      • Noticias Solana
      • Opinión
    • Análisis de Precios
    • Academia Cripto
    • Contacto
    • bandera
    ESP Blockchain Journal
    Home»Noticias»Hidden cryptocurrency miners detected on Windows servers MS-SQL and PHPMyAdmin

    Hidden cryptocurrency miners detected on Windows servers MS-SQL and PHPMyAdmin

    0
    By BlockchainJournal on mayo 30, 2019 Noticias
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The Chinese APT grouping injects cryptocurrency miners and rootkits into MS-SQL and PHPMyAdmin Windows servers around the world. According to specialists from Guardicore Labs , since February 2019, attackers have been able to compromise more than 50,000 servers.

    The malicious campaign was named Nansh0u. The attackers hack Windows MS-SQL and PHPMyAdmin servers using brute-force, and then infect them with malware. Total experts found 20 versions of malicious modules.

    “After successful authorization with administrative rights, the attackers downloaded from the remote server a malicious payload, which through the CVE-2014-4113 vulnerability in the win32k.sys driver was launched with SYSTEM privileges. After that, the malicious module loaded the TurtleCoin cryptocurrency mining program, ”said Guardicore Labs.

    To prevent the completion of the process, the expired digital certificate of the dummy company Hangzhou Hootian Network Technology, issued by Verisign certification center, was used.

    Specialists from Guardicore Labs note that servers with unreliable credentials are in the first place at risk. To check the system for the presence of malware, experts recommend using a free script .

    Earlier in May, the Firefox browser implemented protection against hidden mining.

    Subscribe to BlockchainJournal news on VK !

    << aside id = "unisender_subscribe_form-10" class = "widget unisender_form">

    BlockchainJournal.news

    BlockchainJournal.news

    Featured Network
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    BlockchainJournal

    Related Posts

    Polymarket Integra Oráculos Chainlink para Reducir Riesgos de Manipulación y Fortalecer la Integridad del Mercado

    septiembre 12, 2025

    BlackRock busca tokenizar ETFs tras el éxito de su fondo de Bitcoin

    septiembre 11, 2025

    La SEC aplaza decisiones sobre ETF cripto de BlackRock y Franklin Templeton

    septiembre 11, 2025

    El repunte del 110 % de Worldcoin se enfría por señales de sobrecompra y cansancio del mercado

    septiembre 11, 2025

    El DOJ inicia el decomiso civil de $12M en USDT vinculados a estafas de «pig butchering»

    septiembre 11, 2025

    Backpack Exchange comenzará a operar en varios estados de EE. UU. este año con trading spot como primer servicio

    septiembre 11, 2025
    Buscar
    Facebook X (Twitter) Instagram Pinterest
    © 2025 Blockchainjournal

    Type above and press Enter to search. Press Esc to cancel.

    Utilizamos cookies para asegurar que damos la mejor experiencia al usuario en nuestra web. Si sigues utilizando este sitio asumiremos que estás de acuerdo.