In brief
Unit 42 researchers discovered a new variant of cryptojacking malware named Black-T, authored by TeamTnT. https://t.co/TTdaw0eDdc pic.twitter.com/AyVQGlqByt
— Unit 42 (@Unit42_Intel) October 5, 2020
$88,075.00
-1.92%$3,111.12
-2.20%$213.38
0.06%$633.97
3.01%$0.37887
-3.03%$0.816746
18.43%$1.001
0.09%$3,106.78
-2.24%$0.587949
1.94%$0.178897
1.27%$0.00002441
-4.12%$5.35
1.98%$3,678.41
-2.13%$31.88
-2.92%$87,820.00
-2.08%$3.39
3.74%$0.00002145
9.24%$3,105.70
-2.34%$423.44
-2.89%$13.26
-1.04%$4.87
-3.75%$7.44
-1.46%$5.49
6.73%$83.44
10.97%$11.39
-2.63%$3,270.37
-2.37%$0.994607
-0.80%$8.39
-2.33%$0.152508
-8.87%$0.13633
10.14%$8.15
-3.34%$3.80
-5.74%$503.13
-5.70%$0.146909
14.97%$22.42
2.20%$1.26
-0.57%$22.12
-0.70%$1.002
0.06%$0.366137
-1.56%$1.84
-4.41%$146.16
-2.06%$6.78
-3.45%$43.87
0.51%$0.00003778
4.58%$0.066149
11.85%$161.37
-6.50%$1.009
1.07%$0.716509
2.02%$0.594929
-2.30%$3.94
-2.89%$23.83
-0.74%$0.00022824
0.25%$4.82
-2.94%$0.02484345
-2.84%$1.19
-3.79%$5.05
-0.63%$1.40
-3.24%$1.54
-4.97%$0.68524
-2.09%$3,102.86
-2.39%$5.56
0.18%$0.453629
1.31%$1.83
6.92%$1.75
-9.21%$0.175787
-1.94%$3,465.55
-2.23%$1.76
26.80%$0.547018
-7.30%$3,245.08
-2.47%$0.149462
14.62%$1.095
-5.80%$2.27
-0.74%$0.400104
-2.02%$3,188.45
-2.12%$87,865.00
-1.79%$1.32
-4.54%$10.77
-0.61%$87,911.00
-2.09%$64.00
0.59%$1,434.25
-2.84%$0.149965
3.43%$0.857467
-2.72%$4.65
-6.65%$9.56
0.34%$262.07
-0.30%$16.70
-2.48%$0.02049012
-3.40%$3.15
0.13%$0.00000108
2.69%$1.15
-0.95%$0.02102241
4.80%$3,095.65
-2.62%$0.02537357
-4.57%$5.81
-5.30%$87,620.00
-2.45%$11.94
-0.51%$0.00000244
9.30%$0.01058182
-1.74%$0.442717
-5.10%$62.75
2.33%$0.00215738
-11.16%$0.58338
-0.58%$0.879407
3.02%$87,805.00
-1.67%$0.368168
-1.15%$87,985.00
-1.66%$5.20
-3.28%$0.561305
2.92%$223.53
-0.50%$0.00004295
0.29%$1.22
-5.96%$0.908627
-3.73%$39.56
-1.55%$1.15
-5.24%$0.00785658
8.90%$11.30
1.49%$5.14
-4.24%$28.56
-2.32%$0.694141
1.01%$0.379008
-2.95%$1.085
-3.66%$1.17
0.09%$0.01442858
-1.89%$1.00
0.01%$3.05
-5.97%$0.126711
5.79%$0.775261
29.55%$0.619058
-3.70%$0.719379
0.03%$3,200.62
-2.15%$0.01023001
-6.55%$3,107.21
-2.30%$0.14708
-3.05%$0.283185
0.59%$0.711379
12.82%$251.08
-0.39%$0.996486
0.06%$2.63
-7.69%$0.235993
-2.46%$2,575.95
-0.15%$0.00916256
2.93%$3,108.18
-2.33%$0.333049
1.02%$0.618973
-5.49%$1.99
-3.67%$0.064238
-0.29%$1.28
-6.23%$0.680355
-3.25%$37.65
-2.19%$0.01265745
-1.36%$3,363.66
-2.38%$215.28
-0.28%$16.71
-1.57%$0.00000026
0.78%$31.08
5.54%$0.00009978
0.06%$0.081126
1.22%$1.15
-5.20%$0.07772
-1.05%$1.028
-2.58%$1.82
-2.19%$0.138512
-4.10%$2,568.94
0.04%$3,100.15
-2.51%$87,748.00
-2.17%$1.001
0.14%$1.52
1.15%$0.14149
1.73%$8.71
0.66%$0.999272
0.24%$1.38
-4.58%$3,095.04
-2.25%$0.00140907
-6.86%$0.02797324
60.91%$0.231689
-2.30%$0.04815651
-6.18%$2.44
-3.49%$0.456102
40.58%$3.75
-7.13%$3,105.30
-2.54%$0.03006363
-1.96%$0.00000045
0.26%$3,101.51
-2.39%$1.065
-0.02%$0.239119
2.15%$88,112.00
-2.14%$0.999273
-0.12%$0.144795
3.12%$0.057423
-0.88%$0.390046
1.98%$8.50
-5.10%$0.00
-0.28%$0.01371629
-0.53%$6.74
-3.33%$46.59
-1.91%$0.999846
-0.16%$0.976492
-3.35%$0.402783
15.32%$3,326.54
-2.23%$1.07
0.27%$96.11
-3.46%$87,717.00
-1.61%$3.47
-3.82%$3,207.59
-3.71%$0.056132
-4.82%$0.00115701
0.15%$10.40
-2.92%$1.005
0.07%$0.03900177
1.21%$0.00005462
47.58%$2.83
-8.92%$0.00370796
0.48%$0.295423
-6.49%$3,426.60
-3.18%$0.00681966
-0.70%$0.280529
-1.67%$1,767.43
-1.91%$1.001
0.24%$3.28
-5.21%$0.669218
-4.26%$0.00194994
-1.80%$0.620833
-4.23%$3,304.56
-2.05%$87,673.00
-2.17%$0.066742
-2.35%$1.57
-4.08%$0.335492
-17.62%$0.00413757
1.47%$0.804319
7.88%$0.03348887
8.02%$0.00064264
-2.13%$0.04087873
3.96%$0.32911
-3.28%$0.0168366
-1.37%$86,361.00
-3.29%$37.26
-2.84%$0.454766
-2.66%$0.644556
-1.04%$0.572853
17.39%$1.51
-2.94%$3.96
-3.26%$25.62
1.29%$0.754333
-5.88%$0.401918
6.83%$27.45
-2.12%$0.339803
-0.88%$0.350432
-1.67%$1.15
-8.60%Hackers have updated “Black-T,” a long-running Monero malware, to steal user credentials and take over any other illicit miners on a victim computer, according to a report by cybersecurity firm Unit 42. Such malware behavior was previously unseen.
Unit 42 researchers discovered a new variant of cryptojacking malware named Black-T, authored by TeamTnT. https://t.co/TTdaw0eDdc pic.twitter.com/AyVQGlqByt
— Unit 42 (@Unit42_Intel) October 5, 2020
Crypto malware typically infects computers and use the illicitly gained computing power to mine proof-of-work cryptocurrencies, such as Bitcoin but typically Monero, on behalf of the hackers. Such attacks—known as cryptojacking—are fairly common and are deployed across individual computing networks and whole enterprises.
But like everything in the computing world, there’s an update. Black-T can now find sensitive user information hosted on a victim computer and send it over to the hackers who may then use the illegally gained information for further attacks. These include, but are not limited to, passwords, online credentials, and bank account details.
Black-T uses a hacking tool called “Mimikatz” to scrape plaintext passwords from Windows OS systems, said the report. The tool also allows attackers to hijack user sessions, such as interrupting computer usage when a user is active.
The credential theft update is not all. “Of these new techniques and tactics, most notable are the targeting and stopping of previously unknown cryptojacking worms,” said Unit 42 researcher Nathaniel Quist.
This means that if Black-T finds any computer already hosting a mining malware, it automatically attacks those files, disables the miners, and then in an almost non-benevolent fashion, installs its own cryptojacking program.
Such a step allows a computer’s processing power to be fully used by Black-T (ensuring maximum gains for the hacker).
Quist said that the team behind Black-T may not be stopping with newer updates any time soon. “Unit 42 believes TeamTnT actors are planning on building more sophisticated cryptojacking features into their toolsets – specifically for identifying vulnerable systems within various cloud environments,” Quist noted.
Meanwhile, Unit 42 said protection against such attacks is relatively easy: Users must ensure no files with highly sensitive information are exposed to the internet and that threat software is fully updated and from a reputed brand.