Mar 08 2021

UnityMiner targets unpatched QNAP NAS in cryptocurrency mining campaign

Category: Crypto,CybercrimeDISC @ 11:11 am

Researchers at 360Netlab are warning of a cryptocurrency malware campaign targeting unpatched network-attached storage (NAS) devices.

via the unauthorized remote command execution vulnerability (CVE-2020-2506 & CVE-2020-2507)

Threat actors are exploiting two unauthorized remote command execution vulnerabilities, tracked as CVE-2020-2506 & CVE-2020-2507, in the Helpdesk app that have been fixed by the vendor in October 2020.

The flaws affect QNAP NAS firmware versions prior to August 2020.

The malware involved in the campaign was dubbed UnityMiner by 360 Netlab experts.

“On March 2, 2021, 360Netlab Threat Detection System started to report attacks targeting the widely used QNAP NAS devices via the unauthorized remote command execution vulnerability (CVE-2020-2506 & CVE-2020-2507, upon successful attack, the attacker will gain root privilege on the device and perform malicious mining activities.” reads the analysis published by 360 Netlab.

Threat actors customized the program by hiding the mining process and the real CPU memory resource usage information to hide the malicious activity to QNAP owners that could check their system usage via the WEB management interface.

The mining program is composed of unity_install.sh and Quick.tar.gz. unity_install.sh downloads, set up and execute cryptocurrency miner and hijack the manaRequest.cgi program of the NAS. Quick.tar.gz contains the miner program, the miner configuration file, the miner startup script and the forged manaRequest.cgi. Unity is an XMRig cryptocurrency miner.

360 Netlab shared its findings with the vendor on March 3rd, and due to the possible big impact, the researchers publicly disclosed the attacks.

All NAS devices with QNAP firmware released before August 2020 are currently vulnerable to these attacks. 

The experts reported 4,297,426 QNAP NAS potentially vulnerable devices exposed online, 951,486 having unique IP addresses, most of them are located in the United States, China, and Italy.

Tags: cryptocurrency mining, QNAP NAS, UnityMiner


Mar 04 2021

The Ultimate Blockchain & Bitcoin Guide

Category: CryptoDISC @ 12:15 pm

Let us start with a scenario. Whenever there is an election, we always hear the rumor that there is rigging in the election. In the end, the result is either re-election or a recount of the votes. This whole process is a waste of time and money. If we cannot believe this system the first time, how can we do it a second time? And it is a great scenario where blockchain can be used in real life.

Now, what is the Blockchain?

If you search blockchain on google, you get millions of results that tell us about blockchain. Judging by these millions of findings, it turns out that blockchain technology is one of the cutting-edge and popular technologies. Blockchain is a decentralized, transparent, and trustless system in which there is no need for any middleman or central authority. The best example of this is all companies like banks, where the middleman is involved. Blockchain is a trustless system, and it uses algorithms to build trust within decentralized systems. Often, we hear a word with blockchain is unchangeable, which means that whatever is written once inside the blockchain can never be erased again. Blockchain performs two functions, reading and creating.

Most people think that blockchain is bitcoin and limited to cryptocurrency or only the financial industry uses it. But in fact, blockchain can solve lots of real-world problems like we talked about voting system in the beginning. So, blockchain is an online distributed system in which you store information, and this information can also be access by other parties. All information is store inside a block or container like a register. And all the accounts we call block/register link to each other like a chain, as its name suggests blockchain.

There are three things in each block within the blockchain.

  • Data of the block: This block contains all information like sender, receiver, coins, source, or destination address, etc.
  • Hash of the block datait is known as the backbone of blockchainHash is the encryption technique uses to secure the data. It is never easy to decrypt the hashes as they use a fixed length of alphanumeric for encryption. And the hash value always stays unique.
  • Hash of the previous blockHelp to create a chain with the previous hash of the block.

Source: The Ultimate Blockchain & Bitcoin Guide

Tags: Blockchain & Bitcoin Guide, Blockchain Bubble or Revolution


Feb 25 2021

A Cryptomining botnet abuses Bitcoin blockchain transactions as C2 backup mechanism

Category: Crypto,CybercrimeDISC @ 2:42 pm

Tags: Cryptomining botnet


Feb 22 2021

Nvidia announces official “anti-cryptomining” software drivers

Category: Crypto,MalwareDISC @ 11:53 am

Nvidia, the graphics chip company that wants to buy ARM, made a unusual announcement last week.

The company is about to launch its latest GeForce GPU (graphics processing unit) chip, the RTX 3060, and wants its users know that the chip is “tailored to meet the needs of gamers and those who create digital experiences.”

Nvidia says:

Our GeForce RTX GPUs introduce cutting-edge technologies — such as RTX real-time ray-tracing, DLSS AI-accelerated image upscaling technology, Reflex super-fast response rendering for the best system latency, and many more.

Ray-tracing is an algorithm used in generating synthetic images that are almost unbelievably realistic, correctly modelling complex optical interactions such as reflection, transparency and refraction, but this sort of realism comes at huge computational cost.

You can therefore see why gamers and digital artists might be very keen to get their hands on the latest special-purpose hardware that can speed up the creation of images rendered in this way.

Nvidia announces official “anti-cryptomining” software drivers

Tags: anti-cryptomining


Nov 19 2020

Japan Inc to begin experiments issuing digital yen

Category: CryptoDISC @ 5:48 pm

More than 30 major Japanese firms will begin experiments next year towards issuing a common, private digital currency to promote digitalisation in one of the world’s most cash-loving countries, the group’s organising body said on Thursday.

Source: Japan Inc to begin experiments issuing digital yen



Japan experimenting with digital yen!
httpv://www.youtube.com/watch?v=l-hK_rcL08o






Tags: cryptocurrency, digital yen, Japan


Oct 30 2020

In a first, researchers extract secret key used to encrypt Intel CPU code

Category: Crypto,CryptograghyDISC @ 2:49 pm

Hackers can now reverse-engineer updates or write their own custom firmware.

Source: In a first, researchers extract secret key used to encrypt Intel CPU code





Oct 21 2020

PayPal to allow cryptocurrency buying, selling and shopping on its network

Category: Crypto,CryptograghyDISC @ 10:36 am

PayPal Holdings Inc joined the cryptocurrency market on Wednesday, allowing customers to buy, sell and hold bitcoin and other virtual coins using the U.S. digital payments company’s online wallets.

Source: PayPal to allow cryptocurrency buying, selling and shopping on its network



PayPal to Allow Cryptocurrency Buying, Selling and Shopping on its Network ₿₿₿
httpv://www.youtube.com/watch?v=QdOvU6YzNbU&ab_channel=RulesForRebels










Tags: cryptocurrency, PayPal


« Previous Page