Skip to main content

SambaCry: This Linux Malware Is Turning Machines Into CryptoCurrency Miners

A few weeks ago, we got to know about a vulnerability that dealt with all versions of Samba. While a patch was released to fix this SMB protocol issue, researchers have managed to record the attacks using this flaw to target Linux machines and mine
monero cryptocurrency. The SambaCry malware spreads by scanning for Raspberry Pi devices with open SSH port and unchanged ‘pi’ user password.
Over the last few weeks, WanknaCry ransomware had managed to haunt the users of outdated Windows OS. This has also inspired the Linux users to share memes which roasted Windows users. They assumed that the words Linux and malware don’t go hand in hand.
But, a new malware named Linux.MulDrop.14 has managed to target the Raspberry users who haven’t changed the default passwords of their devices. This vulnerability is exploiting an earlier reported Samba vulnerability.
Targeting the older versions of Rasbian OS, the Linux.MulDrop.14 is a Linux Trojan. It’s a bash script that contains a cryptocurrency mining program, which is compressed using gzip and base 64 encryption.countries_proxyM_en
After infecting the Raspberry Pi-powered devices, the cryptocurrency program is launched. Further, the bash script installs libraries needs for mining cryptocurrency. As this malware was uncovered close to WannaCry outbreak, it’s being termed as EternalRed or SambaCry.
“In an infinite loop, using zmap, the Trojan searches for network nodes with an open port 22, after that it uses sshpass to log into them with the following login:password pair: pi:raspberry, and then—to save and run its copy,” malware’s description on Dr. Web’s website says.
According to the Secure List researchers, SambaCry runs the open source miner utility cpuminer (miderd). The cryptocurrency being mined here is monero.
The actions of malware came into the limelight after a Samba patch was released, which concerned with all versions released since 2010. Using the same flaw that can be exploited using SMB protocol, a hacker can open a pipe on Samba servers and execute malicious code remotely.
At the moment, the actual scale of this malware infection is unknown. But, this news must warn sys admins to update their Samba software and make their systems immune to such attacks.
You can find more information about the SambaCry attack on Secure List blog.

Comments

Follow Us

WHAT'S HOT

VIDEO: KLY & DJ Maphorisa ft. eMTee & Patoranking – SnapThatSh!t

Ambitiouz Entertainment presents the official music video to “SnapThatSh!t” by its budding act, KLYalongside prolific South African producer, Maphorisa, raving South African rapper, eMTee and Nigeria’s music sensation, Patoranking.

How To Install Ubuntu MATE For The Raspberry Pi 2 and Raspberry Pi 3

Ubuntu MATE:  We have done what we can to optimise the build for the Raspberry Pi 2 and Raspberry Pi 3, you can comfortably use applications such as LibreOffice and Firefox. But the microSDHC I/O throughput is a bottleneck so  we  highly  recommend that you use a Class 6 or Class 10 microSDHC  card.  Ubuntu MATE 16.04 also fully supports the built-in Bluetooth and Wifi on

Windows Subsystem For Linux Is Beta No More, Gets “Full Support” In Windows 10 Fall Creators Update

As we told you earlier, WSL on Windows 10  moved out of beta  in August. It still carries the beta tag in Windows 10 Creators Update. Also, it won’t require people to enable developer

KLY Ft. Wizkid – Scrrr Pull Up (Remix)

Starboy, Wizkid blends with KLY as he adds a verse to Kly’s hottest tune Pull up Scrr!!. The remix comes with heavy greatness verse from the starboy boss as he blended another magic lyrics on the self enriched tune. Song Production credit goes to Wichi 1080.