Mit Adylkuzz der zweite konzertierte Angriff
Das neue Modell Cyberwaffen mit klassischer Schadsoftware zu verbinden, wird in naher Zukunft für Datamining und Datendiebstahl genutzt werden
Bisher geben sich die Kriminellen damit zufrieden über Monero einfach schnell Kasse zu machen
WannaCry war erst der Anfang - Mit Adylkuzz ist bereits die nächste Generation von Angriffen, aufbauend auf EternalBlue, im Anrollen. Adylkuzz gehört der Gattung der Cryptocurrency-Miner an, ein Mining-Trojaner, der die Kryptowährung Monero als Endprodukt generiert. Bitdefender hatte erst vor wenigen Tagen nach der weltweiten Attacke der WannaCry-Ransomware gewarnt, dass Angriffe, aufbauend auf EternalBlue Normalität werden würden.
Mit Adylkuzz folgt nun der zweite konzertierte Angriff. Das neue Modell Cyberwaffen mit klassischer Schadsoftware zu verbinden, wird in naher Zukunft für Datamining und Datendiebstahl genutzt werden. Bisher geben sich die Kriminellen damit zufrieden über Monero einfach schnell Kasse zu machen, es ist jedoch nur eine Frage der Zeit, bis andere Parteien mit anderen Interessen auf den Zug aufspringen.
Hier eine kurze Einordnung des Bitdefender Analyseteams:
What's next after Adylkuzz?
A new global threat was discovered recently, the cryptocurrency miner Adylkuzz. Bitdefender warned two days ago that EternalBlue-powered ransomware will become the new normal. Now, the world needs to deal with the second large scale attack. This time we got lucky that we are dealing with a cryptocurrency miner but definitely the things will not stop here. This frame model of combining cyberweapon-grade exploits with classic malware will led in the very near future to data mining and stealing important information. For the moment, the attackers are interested to make the quick dollar but is a matter of time until higher interests will join the party.
Adylkuzz context
As compared to WannaCry, the new threat is harder to detect because it does not give any visual warnings, nor does it interfere with the users’ files. Even if today’s threat has a lower overall impact than the previous attack with crypto ransomware dubbed WannaCry, this is yet another confirmation that cyber-criminals are building a new generation of malware on the EternalBlue SMB exploit allegedly stolen from the NSA.
Due to this particularity of using Server Message Block (SMB) vulnerability, Adylkuzz is more likely to act in an business environment rather than home. However, the profitability of this attack is better at consumer level because cryptocurrency mining is more effective on gaming hardware and multimedia computers. Currently, all the Bitdefender user base is protected.
Ransomware and cryptocurrency miners are the most accessible threats one can build. Computers in public institutions, hospitals and other care facilities are usually rarely updated. If they were not hit by ransomware, these computers will stay vulnerable against the EternalBlue exploit for as long as they remain unpatched. Complex threats can be built on it, from commercial grade malware to more persistent attacks aimed at cyber-espionage, among others.
Why Monero and not Bitcoins?
-Better investment for the future: In the latest months Bitcoin increased 24Prozent while Monero was up 428Prozent. If we look at the last year, Bitcoin was up with 93 percent and Monero with 1720 percent
-Monero is much easy to produce (less processing power from the machine, higher productivity etc)
-Is Monero mining a process that expose less the attackers or is more discreet than Bitcoin mining process?
As a rule of thumb, cryptocurrency miners are much more difficult to spot because they tend to lay low and do their primary job
(Bitdefender: ra)
eingetragen: 21.06.17
Home & Newsletterlauf: 07.07.17
Bitdefender: Kontakt und Steckbrief
Der Informationsanbieter hat seinen Kontakt leider noch nicht freigeschaltet.