Security researchers at Palo Alto Networks uncovered a cryptojacking botnet, tracked as WatchDog, that is targeting Windows and Linux systems.
WatchDog is one of the largest and longest-lasting Monero cryptojacking operations uncovered by security experts, its name comes from the name of a Linux daemon called watchdogd. The WatchDog botnet has been active at least since Jan. 27, 2019 and already mined at least 209 Monero (XMR), valued to be around $32,056 USD.
Palo Alto experts determined that at least 476 systems were compromised by the botnet, mainly Windows and NIX cloud instances, which were involved in mining operations.
The botnet is written in the Go programming language, it is the work of skilled coders.
The bot targets outdated enterprise apps using 33 different exploits to exploit 32 vulnerabilities. Below the list of exploits used by the bot:
The analysis of the config.json files allowed the experts to identify three XMR wallet addresses:
The above XMR wallets addresses are used with at least three public mining pools and one private mining pool to process mining operations.
“It is clear that the WatchDog operators are skilled coders and have enjoyed a relative lack of attention regarding their mining operations. While there is currently no indication of additional cloud compromising activity at present (i.e. the capturing of cloud platform IAM credentials, access ID, or keys), there could be potential for further cloud account compromise. It is highly likely these actors could find IAM-related information on the cloud systems they have already compromised, due to the root and administrative access acquired during the implantation of their cryptojacking software.” concludes Palo Alto.
If you want to receive the weekly Security Affairs Newsletter for free subscribe here.
[adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, botnet)
[adrotate banner=”5″]
[adrotate banner=”13″]
Mozilla addressed two critical Firefox vulnerabilities that could be potentially exploited to access sensitive data…
Japan passed a law allowing preemptive offensive cyber actions, shifting from its pacifist stance to…
James Comey is under investigation for a seashell photo showing “8647,” seen by some as…
Pwn2Own Berlin 2025 wrapped up with $383,750 awarded on the final day, pushing the total…
Security Affairs Malware newsletter includes a collection of the best articles and research on malware…
A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles…
This website uses cookies.