Kitty Cryptocurrency Miner
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Threat details
CVE-2018-7600 is exploited to deliver a Bash script to the target device. This script will then install a PHP file called 'kdrupal' containing a Base 64 encoded backdoor as well as register a cronjob to maintain persistence. Once this is done a variant of the XMrig Monero miner, referred to as kkworker, is installed.
Alongside mining cryptocurrency directly on the compromised server, Kitty will also attempt to distribute another mining script called me0w.js to any hosts that connect to the server.
For further information:
Remediation steps
| Type | Step |
|---|---|
|
CVE-2018-7600 has been rectified in later versions of Drupal Core. Users and administrators should update immediately using the links provided in Drupal's relevant security advisory. Additionally, to prevent and detect an infection ensure that:
|
CVE Vulnerabilities
Last edited: 17 February 2020 12:46 pm