TIAOODAM Cryptocurrency Miner
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, it is unclear how the malware is being distributed, however it may be through fake software downloads. When launched, the MSI file can bypass security features by posing as a legitimate installer that initially runs a script to copy files into a local user directory. The files include a ZIP file cloaked as a decoy icon file, icon.ico, that is unpacked to install extra modules for cryptocurrency mining and obfuscation. It will also attempt to create copies of system kernel files in order to prevent detection of the malware’s APIs.
It will inject its malicious code into three newly spawned svchost.exe processes. The first two are used for persistence to re-download the Windows Installer with a PowerShell command if any of the injected processes are terminated. The third process is used for the miner module. The malware is also equipped with a self-wiping mechanism which deletes every file under its installation directory and will remove any trace of its presence on the system.
Remediation advice
To prevent and detect an infection, ensure that:Remediation steps
| Type | Step |
|---|---|
|
Last edited: 17 February 2020 12:55 pm