Meet Panda, a bootleg cryptocurrency mining crew terrorizing organizations worldwide

[ad_1]
Cybersecurity researchers have profiled a hacking crew named “Panda” believed to have amassed roughly $90,000 price of cryptocurrency by way of distant entry instruments (RATs) and illicit mining malware.
The Cisco Talos Intelligence Group famous that whereas Panda isn’t precisely subtle, it has continued as one of many web’s most energetic attackers in recent times.
Talos researchers highlighted the group’s willingness to constantly exploit susceptible internet purposes worldwide as key to its success. By October final 12 months, a configuration file featured in Panda malware had been downloaded greater than 300,000 instances.
“In addition they often replace their focusing on, utilizing a wide range of exploits to focus on a number of vulnerabilities, and is fast to start out exploiting recognized vulnerabilities shortly after public POCs turn out to be obtainable, turning into a menace to anybody gradual to patch,” stated the agency.
Panda has an enormous bag of RATs (and different exploits)
Panda was first detected in mid-2018 through the wildly profitable “MassMiner” marketing campaign. This was powered by a worm which leveraged a number of in-built exploits, and even brute-forced entry to Microsoft SQL servers, to mine the choice cryptocurrency Monero (XMR).
Now, Panda reportedly makes use of Mimikatz, an open-source program for stealing delicate info from compromised techniques, equivalent to usernames and passwords.

Researchers additionally discovered Panda operates with exploits beforehand utilized by Shadow Brokers, a hacking crew that gained its popularity by publishing info taken from the US Nationwide Safety Company.
Thus far, Talos has confirmed that Panda has hit organizations within the banking, transportation, telecommunications, IT companies, and healthcare industries.
This cryptocurrency mining crew could possibly be of Chinese language origin
Whoever is behind Panda doesn’t actually care an excessive amount of about operational safety. For instance, the group acquired its title as one associated area had been registered to a Chinese language-speaking actor who glided by the title “Panda.”
An analyzed malware pattern additionally requested knowledge utilizing an IP geolocation service which offered the machine’s IP handle and site in Chinese language.
Much more curious, Talos analysts discovered Panda had been exploiting a vulnerability within the ThinkPHP internet framework to unfold its malware. Researchers report this software program is especially common in China.
“Panda’s operational safety stays poor, with a lot of their outdated and present domains all hosted on the identical IP and their TTPs remaining comparatively related all through campaigns,” wrote the agency. “The payloads themselves are additionally not very subtle.”
Nonetheless, Panda’s efforts are stated generated round 1,215 XMR in earnings, which at the moment is price round $90,000 — however the precise quantity earned depends on once they offered their cryptocurrency.
That’s one prolific hacking panda.
Printed September 18, 2019 — 12:12 UTC
[ad_2]
Supply hyperlink





