80,000 computers around the world have been hijacked for mining: Disguise technology is extremely advanced, and they will be repeatedly installed

80,000 computers around the world have been hijacked for mining: Disguise technology is extremely advanced, and they will be repeatedly installed

Source: IT Home

Microsoft has published an alert detailing a new malware variant called Dexphot that has infected more than 80,000 devices since it was first discovered in 2018.

It is reported that hackers mainly use Dexphot to mine cryptocurrencies, not to steal data. Although the virus is relatively harmless, the methods used are very complex, allowing it to evade detection by traditional security tools. One of its techniques is polymorphic camouflage, which can constantly change its footprint on the computer, changing it every 20-30 minutes. It can also reinstall itself to ensure that there is enough time for mining.

Dexphot writes five key files to disk, including an installer with two URLs; an MSI package downloaded from one of the URLs as a password-protected zip file; a loader DRL extracted from the archive; and an encrypted data file where three additional executables are loaded into system processes.

"Besides the installer, other processes that run during execution are legitimate system processes. This can make detection and remediation more difficult," researchers noted. "In later stages, Dexphot targets several other system processes for hollowing, including svchost.exe, tracert.exe, and setup.exe."

Currently, Microsoft has deployed relevant strategies to improve detection rates and prevent attacks, and the number of infected devices has slowly decreased. As of July 31 this year, it has been less than 10,000.


<<:  Ant S9 has reached the shutdown price. It used to make 90 yuan a day, but now it makes 6 yuan.

>>:  New feature of F2Pool | ZEC smart mine jumping

Recommend

How to read the career line of a girl's palm? Different lines can tell your fate

Looking at our leader, we see many different mott...

What does the Tiger Palace represent?

It is said in the physiognomy book that the Yin P...

What does a woman's nose look like when she brings good luck to her husband?

A nose that brings good fortune to the husband is...

Women need to avoid these things if they want to be rich

In life, some people are born with a rich destiny...

What is the Fire sign?

People's destiny is determined by God, and ev...

How to read boys' faces

A person’s goodness and character can be seen fro...

Have you ever met someone with many lines on his hands?

I don’t know if you have ever met someone with a l...

Palmistry and fortune telling: how will your life be?

Palmistry and fortune telling: how will your life...