Jump to content

The Satori Botnet has been retasked to exploit cryptominers.

Bleeping Computer is reporting that the Satori botnet has been retasked to locate unpatched Claymore cryptominer rigs.

 

Quote

The operators of the Satori botnet are mass-scanning the Internet for exposed Ethereum mining rigs, according to three sources in the infosec community who've observed the malicious behavior —SANS ISC, Qihoo 360 Netlab, and GreyNoise Intelligence.

More precisely, crooks are scanning for devices with port 3333 exposed online, a port often used for remote management features by a large number of cryptocurrency-mining equipment.

 

Apparently unpatched rigs have a publicly exposed RPC port. The Satori botnet is currently searching for this port, then taking advantage of it by sending it a command that tells the rig "When I reboot, execute these commands.". then sending another RPC call to reboot. The commands sent change the rigs config to mine a pool under the control of the hackers.

 

This is actually a very smart attack vector. Generally speaking, many cryptominers who have enough money to buy these sort of rigs will use them until they have enough of a profit to afford the latest and greatest with a higher hash rate, then basically leave these on the rack to rot or until the data center unplugs them. I've encountered a few of these over the years working data center ops. So, if you can reconfigure enough of these older rigs that may or may not be used anymore, you can draw a serious revenue stream, which then the Satori botnet masters can turn around and use for R&D into new attack vectors. My hat's off to them, very smart.

 

https://www.bleepingcomputer.com/news/security/the-satori-botnet-is-mass-scanning-for-exposed-ethereum-mining-rigs/

Link to comment
Share on other sites

Link to post
Share on other sites

OP must follow guidelines 

 

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

I'm not sure how this is a violation of the guidelines... it's tech news, and I couldn't find any hits on Google for this when I filtered for just LTT.

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, hyp3rdriv3 said:

I'm not sure how this is a violation of the guidelines... it's tech news, and I couldn't find any hits on Google for this when I filtered for just LTT.

maybe read the thread he linked and see what you forgot?

CPU: AMD Ryzen 5 5600X Heatsink: Gelid Phantom Black GPU: Palit RTX 3060 Ti Dual RAM: Corsair DDR4 2x8GB 3000Mhz mobo: Asus X570-P case: Fractal Design Define C PSU: Superflower Leadex Gold 650W

 

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, VegetableStu said:

you're almost there. you're just missing a quotebox with a short and concise/summised portion of the article

I caught it, thanks!

 

Edit: I thought I had pasted in the quote originally, but I forgot to Ctrl-V it. I'm one of those crazy people who leaps before looking lol

Link to comment
Share on other sites

Link to post
Share on other sites

3 minutes ago, hyp3rdriv3 said:

I'm not sure how this is a violation of the guidelines... it's tech news, and I couldn't find any hits on Google for this when I filtered for just LTT.

its not that its not news, its that you didnt post it properly in the format laid out in the link provided on how to properly format your posts for news posts. 

Community Standards | Fan Control Software

Please make sure to Quote me or @ me to see your reply!

Just because I am a Moderator does not mean I am always right. Please fact check me and verify my answer. 

 

"Black Out"

Ryzen 9 5900x | Full Custom Water Loop | Asus Crosshair VIII Hero (Wi-Fi) | RTX 3090 Founders | Ballistix 32gb 16-18-18-36 3600mhz 

1tb Samsung 970 Evo | 2x 2tb Crucial MX500 SSD | Fractal Design Meshify S2 | Corsair HX1200 PSU

 

Dedicated Streaming Rig

 Ryzen 7 3700x | Asus B450-F Strix | 16gb Gskill Flare X 3200mhz | Corsair RM550x PSU | Asus Strix GTX1070 | 250gb 860 Evo m.2

Phanteks P300A |  Elgato HD60 Pro | Avermedia Live Gamer Duo | Avermedia 4k GC573 Capture Card

 

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, Skiiwee29 said:

its not that its not news, its that you didnt post it properly in the format laid out in the link provided on how to properly format your posts for news posts. 

I caught it, I had the quote in my clipboard but I forgot to paste it. I'm the leap before looking type unfortunately.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×