Skip to main content

PyRoMine Cryptocurrency Miner

A newly observed Python-based cryptocurrency miner, known as PyRoMine, has been seen using the EternalRomance SMB exploit to propagate.

Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

A newly observed Python-based cryptocurrency miner, known as PyRoMine, has been seen using the EternalRomance SMB exploit to propagate.


Affected platforms

The following platforms are known to be affected:

Threat details

This exploit was released alongside the EternalBlue exploit by the Shadow Brokers in 2016.

Delivery is facilitated using the EternalRomance exploit which searches for internet-facing SMB ports (UDP 137, 138 and TCP 137, 139, 445) to spread. Once on a device PyRoMine will download a Visual Basic Script (VBS) to allow traffic over port 3389. This enables it to propagate using Remote Desktop Protocol. PyRoMine will also disable Windows Update features before installing the XMRig mining application.


Remediation steps

Type Step

EternalRomance exploits a vulnerability that has been rectified in Microsoft's Critical Security Bulletin MS17-010. If users do not already have this installed they should do so immediately.

Additionally, if Remote Desktop Protocol (RDP) is not used then ensure port 3389 (TCP/UDP) is blocked at your internet firewall.
If RDP is used, then:

  • Only allow access for authorised RDP users.
  • Enforce strong password policies.
  • Enforce multi-factor authentication.
  • Don't allow RDP access for privileged user accounts.
  • Don’t use generic accounts.
  • Set user accounts with an expiry date.
  • Audit user accounts periodically.
  • Only allow point-to-point connections from specific IP addresses where feasible.
  • Ensure Transport Layer Security (TLS) is up-to-date.
  • Log and monitor all RDP activity and investigate unusual behaviour.
  • Consider only allowing RDP for authorised virtual private network (VPN) connections.

Last edited: 11 January 2022 3:37 pm