Clear, practical technology insights BSOD Code Lookup · Windows Error Code Lookup · Wi-Fi Troubleshooting · PC Troubleshooting Checklist

New Malware-Digging Tool on Linux Devices

A malware author has just created a digital digging tool that infects Linux devices, using open or default Telnet login information.

Table of Contents

A malware author has just created a digital digging tool that infects Linux devices, using open or default Telnet login information.

New Malware-Digging Tool on Linux Devices Overview

The Mining Tool Infects Linux Machines Through Unsafe Telnet Ports

The researchers say trojans use Telnet scanning tools, like the Mirai IoT malware used. BTCMine will randomly scan IPv4 addresses and try to connect via Telnet.

If the port is open or the user uses 1 in the default Telnet certificates, malware connects and runs the command to download and run the actual BTCMine binary file.

This Trojan caught the eyes of Dr. researchers. The web has many references to krebsonsecurity. com, a journalist's personal blog, reputable security researcher Brian Krebs.

This Trojan caught the eyes of Dr Refer to Brian Krebs's name or blog

This is not the first malware to mention Krebs or his blog because both are very popular among security researchers and malware authors. In recent years, malware developers have been quite keen to mock Krebs by putting his name in the code.

Virtual Money Digging Tools Are Increasing

BTCMine is only part of a new trend. Over the past months, researchers from all over the world have discovered many illegal virtual money digging tools. This trend can be seen by the popularity of virtual currencies such as Ethereum, Monero or Zcash. Examples can be mentioned as:

  • CoinMiner - targeting Windows, through NSA's EternalBlue vulnerability.
  • DevilRobber - aiming for a Mac to do it again.
  • Trojan. BtcMine. 1259 - targeting Windows through NSA's DoublePulsar vulnerability.
  • EternalMiner - targets Windows through the SambaCry vulnerability.
  • Adylkuzz - targeting Windows through NSA's EternalBlue vulnerability.
  • Bondnet - targeting Windows Servers via RDP.
  • NsCpuCNMiner - targeting Seagate NSA devices.
  • Many other tools are aimed at Zcash virtual money.

To effectively dig Bitcoin, users need machines with specially optimized hardware but with Ethereum, Monero or Zcash, they can still make a profit using regular computers. Or in BTCMine's case is through Linux machines.

If you are using Telnet to connect to Linux devices, make sure your account has a strong password. If the account has a password, make sure it's not the default password on the device or easily guessed passwords.

Security note: Threat conditions and vendor guidance can change. Install current updates and verify any advisory with the official vendor before taking action.

FAQ

Why does new Malware-Digging Tool on Linux Devices matter?

A malware author has just created a digital digging tool that infects Linux devices, using open or default Telnet login information.

Who may be affected by this issue?

The impact depends on the affected product, version, account, device, or network. Review the article details and the vendor's current advisory to confirm whether your environment is exposed.

How can users reduce the risk?

Install current security updates, use official downloads, enable strong account protection, maintain tested backups, and follow the latest guidance from the relevant vendor.

Discussion

Reader Comments 0

Sign in with email or Google to join the discussion.