ADBminer Android Cryptomining Botnet
A new botnet malware has been observed targeting Android devices. Known as ADBminer, it uses the enrolled devices to mine the Monero cryptocurrency.
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
A new botnet malware has been observed targeting Android devices. Known as ADBminer, it uses the enrolled devices to mine the Monero cryptocurrency.
Affected platforms
The following platforms are known to be affected:
Threat details
ADBminer uses the same code as the Mirai IoT worm to scan for devices with port 5555 open. On Android devices this port is used by the Android Debug Bridge (ADB) tool to allow low-level access to the operating system.
Once a vulnerable device is found ADBminer uses the ADB tool to install itself and begin mining operations. Despite the ease with which
Remediation advice
To avoid botnet infection:Remediation steps
Last edited: 17 February 2020 12:35 pm