25 July 19, 18:58
Quote:A cryptocurrency-mining botnet has recently added a scanner for the BlueKeep RDP protocol vulnerability, Intezer’s security researchers have discovered.
Dubbed WatchBog, the botnet has been active since late 2018 and previously only targeted Linux systems. Largely undetected at the moment, the malware has infected over 4,500 Linux machines in new attacks observed since early June, and it appears that its operators are looking to expand their reach.
The group has been targeting known vulnerabilities in Linux systems, and has recently expanded its implants list to target more servers. It now includes recently published exploits, such as Jira’s CVE-2019-11581, Exim’s CVE-2019-10149, and Solr’s CVE-2019-0192, Intezer says.
Additionally, the crypto-mining botnet now includes a scanner for BlueKeep, a Windows-based kernel vulnerability tracked as CVE–2019-0708 and which allows an attacker to remotely execute code on a vulnerable system.
SOURCE: https://www.securityweek.com/crypto-mini...ep-scanner