Cryptocurrencies

Shake it off! Smominru crypto mining botnet spreads using Taylor Swift pics

A powerful botnet that mines crypto on victims’ networks is being spread using pictures of pop superstar Taylor Swift, cybersecurity experts have warned.

The Smominru botnet infects hardware and steals victims’ credentials, installs a Trojan module and a cryptominer, and propagates inside the network.

Now the hackers behind it are using pictures of Swift, who stars in the new Cats film, to spread the bug, according to cybersecurity firm Sophos.

In a blog post, Sophos’ Gabor Szappanos and Andrew Brandt state: “There’s a pretty good chance everyone who reads this story will have had some degree of interaction with a botnet we call MyKings (and others called DarkCloud or Smominru), whether you know it or not.

“For the past couple of years, this botnet has been a persistent source of nuisance-grade opportunistic attacks against the underpatched, low-hanging fruit of the internet. It’s probably knocking at your firewall right now.

“The botnet has begun to experiment with hiding malware payloads in plain sight, storing the file in an image using a process called steganography.

“In this sample image (the Taylor Swift image), a Windows malware executable (identifiable by its characteristic MZ header bytes and text) appears within the image data in a modified .jpg photo of Taylor Swift.

“MyKings’ operators uploaded this innocuous-looking image file to a public repository and then used it to deliver an update to the botnet.”

The botnet has spread throughout the world

During August, the Smominru botnet infected 90,000 machines around the world, with an infection rate of 4,700 machines per day. Countries with several thousands of infected machines include China, Taiwan, Russia, Brazil, and the US.

As the attacks were untargeted and did not discriminate against industries or targets, they reached victims in various sectors. The largest network belongs to a healthcare provider in Italy with a total of 65 infected hosts.

“Unfortunately, this demonstrates that while many companies spend money on expensive hardware, they are not taking basic security measures, such as patching their running operating system,” the report added.

 

Sam Webb

Sam has nearly two decades of reporting experience and has previously worked for The Mail, The Sun, The Mirror, The Daily Star and numerous trade publications. As a freelancer, he has had stories picked up by media outlets throughout the world including Fox News, The Times and News.com.au. He focuses on foreign news and is keenly interested in how crypto is used by criminals and terrorists.

Disqus Comments Loading...

Recent Posts

3DOS Launching Decentralized “Uber for 3D Printing” on Sui

Grand Cayman, Cayman Islands, 12th September 2024, Chainwire

1 week ago

Flipster Announces Collaboration with Tether

Warsaw, Poland, 20th August 2024, Chainwire

1 month ago

PEXX Announces Strategic Acquisition of Chain Debrief

Singapore, Singapore, 20th August 2024, Chainwire

1 month ago

Kwenta and Perennial Kickstart Arbitrum Expansion with 1.9M ARB

Grand Cayman, Cayman Islands, 26th July 2024, Chainwire

2 months ago

Ethereum could soon surpass the 3K price point

As usual, the crypto market is keeping everyone guessing what could happen next. After an…

2 months ago