Geeks for your information
Cryptomining Malware Uses Rootkit to Hide on Infected Linux Systems - Printable Version

+- Geeks for your information (https://www.geeks.fyi)
+-- Forum: News (https://www.geeks.fyi/forumdisplay.php?fid=105)
+--- Forum: Privacy & Security News (https://www.geeks.fyi/forumdisplay.php?fid=107)
+--- Thread: Cryptomining Malware Uses Rootkit to Hide on Infected Linux Systems (/showthread.php?tid=4467)



Cryptomining Malware Uses Rootkit to Hide on Infected Linux Systems - silversurfer - 10 November 18

Quote:A new cryptocurrency mining malware strain targeting Linux computers and capable of obfuscating itself from both the user and process monitoring tools using a rootkit has been discovered by a team of Trend Micro security researchers.

"We construe that this cryptocurrency-mining malware’s infection vector is a malicious, third-party/unofficial or compromised plugin (i.e., media-streaming software)," says Trend Micro's report.
"Installing one entails granting it admin rights, and in the case of compromised applications, malware can run with the privileges granted to the application. It’s not an uncommon vector, as other Linux cryptocurrency-mining malware tools have also used this as an entry point."

Trend Micro has named the Monero-mining malware Coinminer.Linux.KORKERDS.AB and the rootkit component it uses to hide as Rootkit.Linux.KORKERDS.AA.

Source: https://news.softpedia.com/news/cryptomining-malware-uses-rootkit-to-hide-on-infected-linux-systems-523713.shtml