PowerGhost Trojan and Cryptocurrency Miner
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
The initial PowerShell script is delivered via remote administration tools such as Windows Management Instrumentation (WMI) and Remote Desktop Protocol (RDP), or by a number of exploits. This heavily obfuscated script will then download the XMRig mining module, two libraries required for it to function (msvcp120.dll and msvcr120.dll), the Mimikatz password stealer, a reflective Portable Executable (PE) injector and an EternalBlue shellcode exploit.
Once executed, PowerGhost will contact a command and control server to verify that it is the latest version available and update itself if it is not. It will attempt to propagate across the network using both credentials obtained by Mimikatz and the EternalBlue exploit, before attempting to escalate its privileges. Persistence is maintained by creating a WMI class, containing all PowerGhost modules, that is activated every 90 minutes. The miner is then executed using the PE injection module.
Some variants of PowerGhost will also download a DDoS module although attacks using this module appear to be small in scale, indicating this module is still being tested.
For further information:
Remediation steps
| Type | Step |
|---|---|
|
The EternalBlue vulnerability was fully addressed in Microsoft's MS17-010 security bulletin. Users should install this on their affected systems immediately if they have not done so already. If Remote Desktop Protocol (RDP) is not used, then ensure port 3389 (TCP/UDP) is blocked at your internet firewall. If RDP is used, then:
Additionally, to prevent and detect a trojan infection, ensure that:
|
CVE Vulnerabilities
Last edited: 17 February 2020 12:52 pm