WebCobra Cryptocurrency Miner
WebCobra is a cryptocurrency miner that deploys two different miner modules depending on the running environment of the device.
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
WebCobra is a cryptocurrency miner that deploys two different miner modules depending on the running environment of the device.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, it is unclear how WebCobra is being delivered to devices, although it's known that it is delivered as a Microsoft installer (MSI) file. Once installed, WebCobra will check the running environment and deploys the Cryptonight miner on x86 environments and Claymore’s Zcash miner on x64 environments.
WebCobra use several anti-detection techniques, this includes editing ntdll.dll and user32.dll files to unhook the application programming interfaces (APIs) for some security products and terminating the installation if it detects that certain applications are running.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect a trojan infection, ensure that:
|
Last edited: 7 September 2021 11:37 am