Panchan’s Mining Rig: New Golang Peer-to-Peer Botnet

To avoid detection and reduce traceability, the malware drops its cryptominers as memory-mapped files, without any disk presence.
It also kills the cryptominer processes if it detects any process monitoring.
Based on the malware’s activity and victim geolocation, admin panel language, and the threat actor’s Discord user’s activity, we believe the threat actor is Japanese.
Akamai MFA can mitigate the risk presented by SSH key harvesting.
In addition, configuring strong SSH passwords should stop the malware in its tracks since it uses a very basic list of default passwords to spread.
We have also published IOCs, queries, signatures, and scripts that can be used to test for infection.

Sign Up For Threat Alerts

Loading...
Threats Icon

Jun 30, 2022

YTStealer Malware: YouTube Cookies! Om Nom Nom...

The Dark Web Market for YouTube Account Access In 2006, the term "data is the...

Threats Icon

Jun 27, 2022

Bronze starlight Ransomware Operations Use HUI Loader

The BRONZE RIVERSIDE threat group is likely responsible for stealing intellectual property from Japanese organizations....

Threats Icon

Jun 27, 2022

The Black Basta ransomware is a new...

Although active for just two months, the group already rose to prominence claiming attribution of...

Threats Icon

Jun 27, 2022

Gallium APT Group

Researchers from Palo Alto Networks defined the PingPull RAT as a "difficult-to-detect" backdoor that leverages...

Threats Icon

Jun 26, 2022

US Cert Alert – Malicious Cyber Actors...

The Cybersecurity and Infrastructure Security Agency (CISA) and United States Coast Guard Cyber Command (CGCYBER)...

Threats Icon

Jun 23, 2022

Matanbuchus: Malware-as-a-Service with Demonic Intentions

A new malware-as-a-service (MaaS) called Matanbuchus Loader was discovered in underground markets by Unit42. Malware...

Threats Icon

Jun 22, 2022

Websites Hosting Fake Cracks Spread Updated CopperStealer...

Analysts noticed a new version of CopperStealer and analyzed these samples to be related to...

Threats Icon

Jun 21, 2022

Symbiote Deep-Dive: Analysis of a New, Nearly-Impossible-to-Detect...

Symbiote is a shared object (SO) library that is loaded into all running processes using...

Threats Icon

Jun 19, 2022

HelloXD Ransomware Installing Backdoor on Targeted Systems

Systems are being targeted by a ransomware variant called HelloXD, with the infections also involving...

Threats Icon

Jun 15, 2022

PureCrypter: A Fully-Functional Loader Distributing Remote Access...

PureCrypter is a fully-featured loader being widely sold The malware has been observed distributing a...

Threats Icon

Jun 14, 2022

CERT-IL Alert: an active phishing campaign in...

Recently new information was passed to the CERT-IL team indicating that there is an active...

Threats Icon

Jun 13, 2022

Follina suspected state aligned phishing campaign

Proofpoint blocked a suspected state aligned phishing campaign targeting European gov & local US gov...

Threats Icon

Jun 09, 2022

Newly-Discovered Chinese-linked APT Has Been Quietly Spying...

Cado Labs regularly analyses attacks targeting services running within a honeypot infrastructure. One recent attack...

Threats Icon

Jun 08, 2022

Active Exploitation of Confluence CVE-2022-26134

Atlassian published a security advisory for CVE-2022-26134, a critical unauthenticated remote code execution vulnerability in...

Threats Icon

Jun 07, 2022

Msiexec Impersonation – Exploit Leads to Data...

In this multi-day intrusion, The DFIR Report observed a threat actor gain initial access to...