Connect with us

Hi, what are you looking for?

HEADLINES

Sophos identifies source of ‘MrbMiner’ attacks targeting database servers

MrbMiner is a recently discovered cryptominer that targets internet-facing database servers (SQL servers) and downloads and installs a cryptominer. Database servers are an attractive target for cryptojackers because they are used for resource intensive activity and therefore have powerful processing capability.

Sophos, a global player in next-generation cybersecurity, published a new report on MrbMiner, “MrbMiner: Cryptojacking to bypass international sanctions,” tracking its origin and management to a small software development company based in Iran. 

MrbMiner is a recently discovered cryptominer that targets internet-facing database servers (SQL servers) and downloads and installs a cryptominer. Database servers are an attractive target for cryptojackers because they are used for resource intensive activity and therefore have powerful processing capability. 

SophosLabs found that the attackers used multiple routes to install the malicious mining software on a targeted server, with the cryptominer payload and configuration files packed into deliberately mis-named zip archive files. 

The name of an Iran-based software company was hardcoded into the miner’s main configuration file. This domain is connected to many other zip files also containing copies of the miner. These zip files have in turn been downloaded from other domains, one of which is mrbftp.xyz. 

Advertisement. Scroll to continue reading.

“In many ways, MrbMiner’s operations appear typical of most cryptominer attacks we’ve seen targeting internet-facing servers,” said Gabor Szappanos, threat research director, SophosLabs. “The difference here is that the attacker appears to have thrown caution to the wind when it comes to concealing their identity. Many of the records relating to the miner’s configuration, its domains and IP addresses, signpost to a single point of origin: a small software company based in Iran.

“In an age of multi-million dollar ransomware attacks that bring organizations to their knees it can be easy to discount cryptojacking as a nuisance rather than a serious threat, but that would be a mistake. Cryptojacking is a silent and invisible threat that is easy to implement and very difficult to detect. Further, once a system has been compromised it presents an open door for other threats, such as ransomware. It is therefore important to stop cryptojacking in its tracks. Look out for signs such as a reduction in computer speed and performance, increased electricity use, devices overheating and increased demands on the CPU.”

Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

HEADLINES

A calamity fund is designed to provide financial relief in these challenging times, ensuring that you have the resources needed to recover quickly and...

HEADLINES

This is in line with the Philippine government’s efforts to strengthen the security and resilience of the country’s cyberspace under the National Cybersecurity Plan...

HEADLINES

The report shows that 86% of Oracle Java users are migrating all or some of their use with reasons including cost, a preference for...

HEADLINES

By extending Platform Equinix to the Philippines, local businesses can expand globally across 71 markets while overseas companies can seize the digital opportunities presented...

HEADLINES

Converge is breaking ground on Ribbon’s 5 nanometer (nm) - 140Gbaud transmission chipset that will expand its fiber network capacity from its existing 800...

HEADLINES

Alipay+ is the Official Payment Partner of the UEFA EURO 2024, and connects leading e-wallets and bank apps, including European partners like Bluecode and...

HEADLINES

Powered by the all-in-one Genesys Cloudplatform , the ePLDT Next-Gen Contact Center as-a-Service (CCaaS) uses AI to provide a 360-degree view of the end-to-end...

HEADLINES

The upcoming Paris Olympics, the first in-person summer Games since pandemic restrictions were lifted, are expected to attract thousands of tourists. Amid the event,...

Advertisement