Buy PresaleClam 333%
Ad
Buy Presale

Play. Win. Earn.

  • Get 333% up to €3000 + 333 FS
  • Play 6000+ Games (Slots, Live Casino, Sportsbook)
  • Rakeback on Every Bet + Weekly Bonuses
  • Instant Crypto Payouts (BTC, ETH, USDT & more)
  • Provably Fair Games & Secure Platform
Start Playing
EN

Monero [XMR] Mining Malware in Action with Drupal Vulnerability Exploitation

Sagar Saxena
June 22, 2018 Updated May 14, 2024
Passionate about Blockchain and has been researching and writing about the Blockchain technology for over a year now. Also holds expertise in digital marketing.
Read full bio
Why Trust CoinGape
CoinGape has covered the cryptocurrency industry since 2017, aiming to provide informative insights to our readers. Our journal analysts bring years of experience in market analysis and blockchain technology to ensure factual accuracy and balanced reporting. By following our Editorial Policy, our writers verify every source, fact-check each story, rely on reputable sources, and attribute quotes and media correctly. We also follow a rigorous Review Methodology when evaluating exchanges and tools. From emerging blockchain projects and coin launches to industry events and technical developments, we cover all facets of the digital asset space with unwavering commitment to timely, relevant information.

Hackers are exploiting the Drupal vulnerability to attack the networks and activate Monero (XMR) mining malware. The same vulnerability that has been patched in April, is yet again exploited.

Hackers exploiting Drupal vulnerability again

Privacy-focused Monero is certainly favourable among the cybercriminals as yet again the criminals are trying to drop the Monero mining malware into the vulnerable systems by leveraging the Drupal vulnerability. A security flaw CVE-2018-7602 has been found in Drupal, a content management framework that has been exploited. The attackers are trying to run the affected systems into Monero mining bots. These attacks can lead to a number of threats apart from slowing the system performance and stealing the resources.

This is not the first time the Drupal vulnerability has been exploited, back in April, this year only it has been patched. A remote code execution, CVE-2018-7602 affects the 7 and 8 version of Drupal. In order to exploit this vulnerability, a shell script has been downloaded that recovers an  Executable and Linkable Format-based (ELF) downloader. This then adds a crontab entry that basically updates itself automatically.

Also, read: Monero (XMR), Siacoin (SC), NEM (XEM) & Aeternity (AE) Gets New Listing, Price Analysis

Save your systems

During the process, it retrieves and installs a Monero mining application in the affected machine. A modified version of XMRig, it is one of the most commonly used variants in Monero mining attacks. Apparently, the downloader even checks the target system to see if it the machine to be compromised or not. Once miner starts running, it even changes its name.

The attacks aren’t running amok, they take proper precautions by hiding behind the Tor network. Reportedly, the same IP address has initiated 810 attacks that have been blocked by Trend Micro. However, it’s not confirmed if all of these attacks are Monero related or not. Apparently, this IP address exploits Heartbleed (CVE-2014-0160), ShellShock (CVE-2014-6271) memory leak flaw in Apache (CVE-2004-0113), WEB GoAhead (CVE-2017-5674) and others.

By patching and updating the Drupal core, one can fix this vulnerability for which the guidelines are provided on the security bulletin of Drupal.

What do you think of the repeated attempts by cybercriminals to activate Monero mining malware? Share your thoughts with us!

coingape google news

Why Trust CoinGape

CoinGape has covered the cryptocurrency industry since 2017, aiming to provide informative insights Read more… to our readers. Our journal analysts bring years of experience in market analysis and blockchain technology to ensure factual accuracy and balanced reporting. By following our Editorial Policy, our writers verify every source, fact-check each story, rely on reputable sources, and attribute quotes and media correctly. We also follow a rigorous Review Methodology when evaluating exchanges and tools. From emerging blockchain projects and coin launches to industry events and technical developments, we cover all facets of the digital asset space with unwavering commitment to timely, relevant information.

Newsletter
Your crypto brief.
Delivered every day.
  • Insights that move markets
  • 100,000 active subscribers
By signing-up you agree to our Terms and Conditions and Privacy Policy.
About Author
About Author
Passionate about Blockchain and has been researching and writing about the Blockchain technology for over a year now. Also holds expertise in digital marketing.
Investment disclaimer: The content reflects the author’s personal views and current market conditions. Please conduct your own research before investing in cryptocurrencies, as neither the author nor the publication is responsible for any financial losses.
Ad Disclosure: This site may feature sponsored content and affiliate links. All advertisements are clearly labeled, and ad partners have no influence over our editorial content.