New Malware Miner Sneakily Hides When Task Manager Is Open
Meet "Norman" – a new variant of monero-mining malware that employs crafty tricks to avoid being spotted.
:format(jpg)/cloudfront-us-east-1.images.arcpublishing.com/coindesk/DOLUYR2U75AF3H3SQAFTXORMDI.jpg)
/arc-photo-coindesk/arc2-prod/public/LXF2COBSKBCNHNRE3WTK2BZ7GE.png)
Meet "Norman" – a new variant of monero-mining malware that employs crafty tricks to avoid being spotted.
The malicious code was identified by researchers at data security firm Varonis when investigating a crypto-miner infestation at a "mid-size company."
"Almost every server and workstation was infected with malware. Most were generic variants of cryptominers. Some were password dumping tools, some were hidden PHP shells, and some had been present for several years," the firm said.
However, one miner stood out – Norman, as the team dubbed it.
Norman's payload has two primary functions: execute its XMRig-based crypto-miner and avoid detection.
After injection, it overwrites its entry in explorer.exe to conceal evidence of its presence. It also stops operating the miner when the PC's user opens Task Manager (see image below). Re-injecting itself once Task Manager is not running.
:format(jpg)/cloudfront-us-east-1.images.arcpublishing.com/coindesk/2TTDJK4CRNFX5IULKINLNV4Z7U.gif)
The miner element of the malware is based on the openly available XMRig code hosted on GitHib. However, Varonis found that its monero (XMR) address is blocked by the mining pool it links to, and hence is effectively disabled.
The researchers further found a PHP shell, possibly linked to Norman, that "that continually connects to a command-and-control (C&C) server." Web shells can allow remote access to a system on which they are installed.
However, the team found that, when they ran the code, it entered a loop awaiting commands and none had been received at time of writing.
The report also notes that Norman may have been created in France or a French-speaking nation. "The SFX file had comments in French, which indicate that the author used a French version of WinRAR to create the file," said Varonis.
Hat tip: TNW
Cat in a box image via Shutterstock; gif animation via Varonis
Disclosure
Please note that our privacy policy, terms of use, cookies, and do not sell my personal information has been updated.
The leader in news and information on cryptocurrency, digital assets and the future of money, CoinDesk is an award-winning media outlet that strives for the highest journalistic standards and abides by a strict set of editorial policies. In November 2023, CoinDesk was acquired by Bullish group, owner of Bullish, a regulated, institutional digital assets exchange. Bullish group is majority owned by Block.one; both groups have interests in a variety of blockchain and digital asset businesses and significant holdings of digital assets, including bitcoin. CoinDesk operates as an independent subsidiary, and an editorial committee, chaired by a former editor-in-chief of The Wall Street Journal, is being formed to support journalistic integrity.
Learn more about Consensus 2024, CoinDesk's longest-running and most influential event that brings together all sides of crypto, blockchain and Web3. Head to consensus.coindesk.com to register and buy your pass now.