Massive Botnet Turns Windows Machines into Miners
ID: 9dc5296e-a9b4-5693-b87a-01f36aa7334b
STIX ID: report--9dc5296e-a9b4-5693-b87a-01f36aa7334b
Feed Name: Binary Defense Blog
Threat Score
Researchers discovered the Smominru botnet that compromised over half a million Windows devices using the EternalBlue exploit (and EsteemAudit against RDP on legacy systems) to deploy Monero miners; it has mined approximately 8,900 XMR (~$2.8M–$3.6M). The botnet exhibits worm-like propagation, can regenerate after partial takedowns, and is concentrated in Russia, India, and Taiwan, though the operators remain unidentified.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
