Summary
PsMiner is a newly observed, Go-based, cryptocurrency mining worm.
Affected platforms
The following platforms are known to be affected:
Threat details
The threat actors operating PsMiner use several known exploits for multiple high-risk vulnerabilities, as well as brute-force attacks on systems with weak password configurations, to gain access.
Once delivered, PsMiner will execute a PowerShell command to download and execute a secondary module, WindowsUpdate.ps1, which is responsible for downloading and executing the mining and worm modules. The malware uses the open source mining tool, XMRig CPU Miner, to harvest the power of infected machines to mine for the Monroe cryptocurrency.
For further information:
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect an infection, ensure that:
|
CVE Vulnerabilities
Last edited: 14 February 2020 2:53 pm