BSV
$54.2
Vol 32.29m
-4.02%
BTC
$96892
Vol 44780.89m
-1.68%
BCH
$458.95
Vol 365.58m
-2.43%
LTC
$101.81
Vol 903.38m
-1.38%
DOGE
$0.32
Vol 5744.17m
-5.15%
Getting your Trinity Audio player ready...

A new form of cryptojacking malware has been identified for the first time, described as the work of “highly professional software developers.”

According to reports from cybersecurity research firm Guardicore Labs, the FritzFrog malware botnet is highly sophisticated, and has already infected tens of millions of IP addresses worldwide.

The bot has mainly been targeting banks, educational institutions, medical institutions and government agencies, with the report finding that the malware had already compromised “over 500 SSH servers, including those of known high-education institutions in the U.S. and Europe, and a railway company.”

FritzFrog uses brute-force attacks to gain access to servers, before running XMRig mining software. This in turn uses the hacked organization’s resources to mine for privacy coin Monero, which delivers the hackers their pay day.

According to the report, FritzFrog appears unique among cryptojacking malwares in that it is hidden within P2P networks, which makes it much more difficult to identify.

“Unlike other P2P botnets, FritzFrog combines a set of properties that makes it unique: it is fileless, as it assembles and executes payloads in-memory. It is more aggressive in its brute-force attempts, yet stays efficient by distributing targets evenly within the network.”

The report also noted that the “p2p implementation was written from scratch,” suggesting it was the work of “highly professional software developers.”

The malware is the latest malicious crypto mining script to be discovered, at a time when this method of hacking is on the rise. Servers and networks across the world are being compromised by these types of attacks on a daily basis, with hackers illegitimately harvesting resources to power their Monero mining operations.

It follows on from a series of similar attacks earlier this year, which saw cryptojacking attempts on supercomputers at similar institutions. The malware brought a number of these supercomputers offline at the time, in some cases impacting their work towards research into COVID-19.

Recommended for you

Google unveils ‘Willow’; Bernstein downplays quantum threat to Bitcoin
Google claims that Willow can eliminate common errors associated with quantum computing, while Bernstein analysts noted that Willow’s 105 qubits...
December 18, 2024
WhatsOnChain adds support for 1Sat Ordinals with new API set
WhatsOnChain now supports the 1Sat Ordinals with a set of APIs in beta testing; with this new development, developers can...
December 13, 2024
Advertisement
Advertisement
Advertisement