Using BT tools to spread mining programs, nearly 400,000 PCs have become mining machines

Using BT tools to spread mining programs, nearly 400,000 PCs have become mining machines

Microsoft said the MediaGet compromise was a carefully planned operation that began in mid-February, with attackers using advanced cross-process injection, persistence mechanisms and evasion techniques.

Microsoft discovered that mediaget.exe obtained the signature of another software company's certificate and downloaded the program update.exe from the MediaGet server, which then installed an unsigned pirated version of mediaget.exe. update.exe is an InnoSetup SFX file. After obtaining the signature of another software company, it downloaded the pirated version of mediaget.exe from an external C&C server. It is 98% similar to the normal software, and the only difference is that it contains a mining backdoor.

Currently, MediaGet is used by a large number of users abroad, and this attack may affect more than 400,000 computers worldwide.


<<:  What is PoS mining? How is it different from Bitcoin’s PoW mining?

>>:  Bitcoin costs $8,000, report says cryptocurrency mining is no longer profitable

Recommend

What kind of facial features of a woman represent her wildness?

The so-called wild and sexy woman is actually a m...

Fingerprint analysis of your destined lover

Fingerprint analysis of your destined lover 4 Dou...

Another victory! South Korean exchange Korbit announced support for Ethereum

Since the Japanese Coincheck exchange announced i...

Men who are not handsome but have good fortunes have good fortunes.

Handsome men are more likely to attract attention...

Fees of each mining pool currency

To facilitate sharing, the information is display...

Analysis of the facial features of sinister people

People often say that time reveals a person's...

What does the secret of phoenix eye pattern mean?

What does the secret of phoenix eye pattern mean?...