Outlaw hacking group kills existing cryptocurrency miners in enterprise server attacks

Outlaw hacking group kills existing cryptocurrency miners in enterprise server attacks 1

The Outlaw hacking group has remerged after months of quiet with an upgraded toolset designed for data theft and for plundering enterprise resources in the quest for cryptocurrency. 

Outlaw, first spotted back in 2018, is a threat group that has been in testing and malware development stages over the past year. 

In June 2019, researchers from Trend Micro said that unexecuted, malicious commands and clues in shell script components of a botnet developed by the cyberattackers indicated that Chinese victims were likely guinea pigs for botnet-based cryptocurrency mining campaigns.

See also: Outlaw hackers return with cryptocurrency mining botnet

The botnet is equipped with a Monero (XMR) miner and following a period of inactivity has now been bolstered with improvements, including the ability to find and eradicate existing cryptocurrency miners on infected systems. 

Trend Micro observed an uptick in activity in December, in which attacks moved from the Chinese testing ground to the US and Europe, the cybersecurity firm said in a blog post on Monday. 

According to the team, other upgrades have also taken place including “expanded scanner parameters and targets, looped execution of files via error messages, improved evasion techniques for scanning activities, and improved mining profits by killing off both the competition and their own previous miners.”

CNET: Foreign hackers are targeting more US government agencies, report says

Outlaw is targeting Linux- and Unix-based operating systems, Internet of Things (IoT) devices, and vulnerable corporate servers. 

Currently, Outlaw is exploring CVE-2016-8655 and the Dirty COW exploit (CVE-2016-5195) as potential entryways for exploit kits, alongside PHP-based web shells used to try and crack servers with poor SSH and Telnet credentials. These vulnerabilities are years old, and so by focusing on them, this could indicate that Outlaw wants to stay under the radar by targeting servers with next to no security or patch processes.

“It appears that they’re going after enterprises who have yet to patch their systems, as well as companies with Internet-facing systems with weak to no monitoring of traffic and activities,” the researchers say. 

TechRepublic: Kubernetes rollouts: 5 security best practices

Samples obtained by the team suggest that cryptocurrency mining is not the only avenue for illicit revenue that Outlaw is exploring. In addition, malware has been found that focuses on the theft of data from compromised servers, mainly geared towards the automotive and financial sectors. This information could then potentially be sold on for a profit. 

Enterprise servers may not be the only new targets that Outlaw is examining. The researchers also found evidence of Android APKs and Android Debug Bridge (ADB) commands that could be used to force Android-based smart television sets to mine for cryptocurrency. 

Previous and related coverage

Have a tip? Get in touch securely via WhatsApp | Signal at +447713 025 499, or over at Keybase: charlie0

About the author

E-Crypto News was developed to assist all cryptocurrency investors in developing profitable cryptocurrency portfolios through the provision of timely and much-needed information. Investments in cryptocurrency require a level of detail, sensitivity, and accuracy that isn’t required in any other market and as such, we’ve developed our databases to help fill in information gaps.

Related Posts

E-Crypto News Executive Interviews

Automated trading with HaasBot Crypto Trading Bots

Crypto Scams

Millions in Cryptocurrency Stolen by Scammers in the Last Month According to Tenable Research
November 24, 2021
Behind The Scenes: How this Crypto Community Responded to + $50m Hack
October 18, 2021
Crypto Scams
Crypto Scams Still Persistent In 2021, SEC Warns About Red Flags To Watch
September 9, 2021
Poly Network
Here’s How Hackers Stole Over $600 million in the Poly Network Attack
August 12, 2021
The World’s Most Infamous Crypto Hacks and Scams
July 31, 2021

Blockchain/Cryptocurrency Questions and Answers

How Does Bitcoin Casino Work + 2021 Beginner’s Guide
November 8, 2021
How to Buy and Sell Cryptocurrency
November 8, 2021
What Are Bitcoin Futures And How Will They Work In 2022?
November 4, 2021
The Unconventional Guide to Ethereum
October 28, 2021
ICo Presale
The Science Behind ICO Presales…
October 14, 2021

CryptoCurrencyUSDChange 1hChange 24hChange 7d
Bitcoin37,028 0.70 % 8.74 % 12.46 %
Ethereum2,449.9 0.48 % 8.98 % 23.84 %
Tether1.010 0.40 % 0.71 % 0.36 %
Binance Coin374.22 0.11 % 7.04 % 21.45 %
USD Coin1.010 0.23 % 0.75 % 0.28 %
Cardano1.050 0.98 % 4.38 % 34.12 %
Solana94.07 0.56 % 11.25 % 32.83 %
XRP0.6095 0.50 % 6.03 % 20.30 %
Terra64.86 0.74 % 0.90 % 16.11 %
Polkadot18.70 0.62 % 11.29 % 27.37 %

Bitcoin (BTC) $ 36,901.00
Ethereum (ETH) $ 2,450.21
Tether (USDT) $ 1.00
Binance Coin (BNB) $ 374.23
USD Coin (USDC) $ 1.00
Cardano (ADA) $ 1.04
Solana (SOL) $ 94.30
XRP (XRP) $ 0.608835
Terra (LUNA) $ 64.77
Polkadot (DOT) $ 18.69