GreedyAntd Cryptocurrency Miner
First observed in early 2019, GreedyAntd (also known as Antd) is a modular cryptocurrency mining malware created by the Pacha advanced persistent threat group.
Summary
First observed in early 2019, GreedyAntd (also known as Antd) is a modular cryptocurrency mining malware created by the Pacha advanced persistent threat group.
Affected platforms
The following platforms are known to be affected:
Threat details
GreedyAntd is delivered manually, with Pacha scanning the Internet for vulnerable WordPress or PhpMyAdmin instances before deploying several exploits for known vulnerabilities to gain access to the underlying server. Once this is done they will drop a backdoor through which GreedyAntd is installed.
Once delivered, GreedyAntd will create a Systemd service to gain persistence before creating a proxy service to mask disguise it's operations. It will then deploy a heavily modified XMRig variant using a configuration file downloaded from a command and control server. A separate list is also downloaded and used to terminate other mining processes on the system.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect an infection, ensure that:
|
Last edited: 14 February 2020 2:43 pm