Close Menu
    X (Twitter)
    Blockchain Journal
    • News
      • Blockchain News
      • Bitcoin News
      • Ethereum News
      • NFT
      • DeFi News
      • Polkadot News
      • Chainlink News
      • Ripple News
      • Cardano News
      • EOS News
      • Litecoin News
      • Monero News
      • Stellar News
      • Tron News
      • Press Releases
      • Opinion
      • Sponsored
    • Price Analisys
    • Learn Crypto
    • Contact
    • bandera
    Facebook X (Twitter) Instagram
    Blockchain Journal
    Home » Trend Micro researchers have discovered an unusual hidden miner under Linux

    Trend Micro researchers have discovered an unusual hidden miner under Linux

    0
    By BlockchainJournal on November 12, 2018 News
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Analysts specializing in cybersecurity Japanese company Trend Micro have discovered a cryptocurrency miner KORKERDS, which is characterized by somewhat atypical behavior. This is reported on the company's website .

    Researchers have not yet determined exactly how the threat spreads. However, most likely, its download occurs after installing some software or through a compromised plugin.

    Researchers assigned the Coinminer.Linux.KORKERDS.AB identifier to the miner (XMR), a mining cryptocurrency miner. It is noteworthy that another component is also used – the rootkit (Rootkit.Linux.KORKERDS.AA), which “hides” the mining process from monitoring tools.

    After starting the work of the hidden miner in the system, the CPU load increases to 100%. However, the user is not easy to find out the reason for this. The situation is complicated by a rootkit that uses hooks for the readdir and readdir64 APIs, and the libc library. The normal library file is overwritten, with readdir being replaced with a fake version.

    The malicious version of readdir is used to hide the mining process (kworkerds). After that, it becomes much more difficult to identify a miner, despite the fact that the processor load indicates suspicious activity.

    According to the researchers, the new miner may pose a threat not only to servers, but also to ordinary Linux users.

    Recall that in June, analysts of Palo Alto Networks reported that 5% of Monero coins were mined using hidden mining .

    Subscribe to BlockchainJournal news in Telegram: BlockchainJournal Live – the entire news feed, BlockchainJournal – the most important news and polls.

    << aside id = "unisender_subscribe_form-10" class = "widget unisender_form">

    BlockchainJournal.news

    Featured Work
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    BlockchainJournal

    Related Posts

    ARK Invest Unloads Coinbase and GBTC Shares by Millions Amid Market Boom

    December 6, 20232 Mins Read

    GBTC Discount Shrinks as Bitcoin Price Surges

    December 6, 20232 Mins Read

    IBM Introduces OSO, Designed for Cold Storage of Digital Assets

    December 6, 20232 Mins Read

    Marathon Digital Produced 1,187 Bitcoins in November and Held 14,025 Unrestricted BTC

    December 5, 20232 Mins Read

    Volume Counterfeiting Allegations Rock RATS Token on Gate Exchange

    December 5, 20232 Mins Read

    A New Era for Cryptocurrency: Zodia Custody’s Integration with Harmonize

    December 4, 20232 Mins Read

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © 2025 Blockchain Journal

    Type above and press Enter to search. Press Esc to cancel.

    We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.