Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Official RVTools Website Hacked to deliver malicious Bumblebe software

May 19, 2025

Band

May 19, 2025

Firefox Patches 2 Zero-Day

May 19, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » More than 4000 IPS IP aimed at attacking the brute force to deploy information about theft and cry
Global Security

More than 4000 IPS IP aimed at attacking the brute force to deploy information about theft and cry

AdminBy AdminMarch 4, 2025No Comments3 Mins Read
Info Stealers and Crypto Miners
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


04 March 2025Red LakshmananNetwork safety / ransom

Information about theft and crystals

Internet services providers (providers) in China and the West coast of the United States have been the goal of a massive company that deployed the theft of cryptocurrency information and miners on compromised hosts.

The resulting data come from the SPLUNK research group, which states that the activity also led to the delivery of various binary files that facilitate the data of the data, as well as the ways to establish persistence in the systems.

Unknown threaten subjects conducted “minimum intrusive operations to avoid detection, except for artifacts created in accounts that have already been compromised”, a company owned by Cisco – Note In a technical report published last week.

Cybersecurity

“This actor also moves and turns first, using the tools that depend and run in scripting languages ​​(such as Python and PowerShell), allowing the actor to perform in limited environments and use API bells (such as telegram) for C2 operations (commands and control).”

The attacks were observed using gross attacks that exploit weak powers. These invasion attempts arise with IP -units related to Eastern Europe. More than 4,000 IP providers are said to have been specifically oriented.

After receiving its initial access conditions, it was found that the attacks are rejecting several executable files through PowerShell to conduct a network scan, theft of Xmrig cryptocurrency mining, abusing the victim’s computing resources.

Prior to the useful load, there is a preparatory stage, which includes disabling safety products and stopping services related to Cryptominer.

Malicious software for theft, in addition to show the ability to shoot screenshots, serves like Malicious software for Clipper This is designed for theft of the contents of the clipboard, looking for a wallet for cryptocurrencies such as Bitcoin (BTC), Ethereum (ETH), Binance Bep2 (ETHBEP2), Litecoin (LTC) and TRON (TRX).

In the future, the collected information is released to the Telegram bot. Also fell on an infected car – a binary, which in turn launches additional useful loads –

Cybersecurity
  • Auto.exe, which is designed to download the password list (Pass.txt) and the IP address list
  • Masscan.exe, multiple tool

“The actor is aimed at certain Cidrs ISPs providents located on the West coast of the United States and China,” Rublko said.

“These IP were directed using the Masscan tool, which allows the operators to scan a large number of IP addresses that can be conducted in the future for open ports and accounting attacks.”

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Official RVTools Website Hacked to deliver malicious Bumblebe software

May 19, 2025

Band

May 19, 2025

Firefox Patches 2 Zero-Day

May 19, 2025

Why CTEM – This is a winning rate for CISO in 2025

May 19, 2025

New Httpbot Botnet Launches 200+ Precision Ddos Attacks to Game and Technology Sectors

May 16, 2025

10 best practices for effective data protection

May 16, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Official RVTools Website Hacked to deliver malicious Bumblebe software

May 19, 2025

Band

May 19, 2025

Firefox Patches 2 Zero-Day

May 19, 2025

Why CTEM – This is a winning rate for CISO in 2025

May 19, 2025

New Httpbot Botnet Launches 200+ Precision Ddos Attacks to Game and Technology Sectors

May 16, 2025

10 best practices for effective data protection

May 16, 2025

Rat Remcos delivered via LNK files and mshta in attacks based on PowerShell

May 16, 2025

Researchers put up new flaws of the Intel processor that allows for memory leaks and attacks Spectre V2

May 16, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Official RVTools Website Hacked to deliver malicious Bumblebe software

May 19, 2025

Band

May 19, 2025

Firefox Patches 2 Zero-Day

May 19, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.