Rarog Cryptocurrency Miner
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, it is unclear how Rarog is delivered, although there are unconfirmed reports indicating it is propagated through phishing campaigns and drive-by-downloads. When downloaded Rarog will write itself to the local drive before writing itself to the file system. It will also check for the presence of certain security applications and strings and deletes itself if any are detected.
After installation Rarog deletes itself from the local disk before communicating with its command and control server and initiating its mining module. It also has the ability to load and execute additional dynamic link libraries as well as infect connected USB devices for further propagation.
Remediation advice
To prevent and detect an infection, ensure that:Remediation steps
| Type | Step |
|---|---|
|
Last edited: 17 February 2020 12:53 pm