Linux Cryptomining Trojan using Rootkits
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Threat details
At the time of publication, it is not known what software is installing the malware. However, it is believed to stem from an unofficial or compromised plugin such as media-streaming software. Once installed, the program will download and execute a series of shell scripts. An initial ELF file downloads and executes the first shell script, which then downloads and executes another shell script. The second script downloads and installs the miner and rootkit.
When running, the miner will utilise 100% CPU but users will not be able to detect which process is using it. The rootkit blocks the access of the process monitoring tools to the files located in the /proc/{PID} directories, resulting in the processes indicative of cryptocurrency mining malware being hidden.
Remediation advice
To prevent and detect an infection, ensure that:Remediation steps
| Type | Step |
|---|---|
|
Last edited: 17 February 2020 12:47 pm