{"id":171576,"date":"2019-09-19T00:30:01","date_gmt":"2019-09-18T21:30:01","guid":{"rendered":"http:\/\/ww-vb.mine.nu\/w108\/meet-panda-an-illicit-cryptocurrency-mining-crew-terrorizing-organizations-worldwide\/"},"modified":"2019-09-19T00:30:05","modified_gmt":"2019-09-18T21:30:05","slug":"meet-panda-an-illicit-cryptocurrency-mining-crew-terrorizing-organizations-worldwide","status":"publish","type":"post","link":"https:\/\/hameed.nwar.uk\/sa\/meet-panda-an-illicit-cryptocurrency-mining-crew-terrorizing-organizations-worldwide\/","title":{"rendered":"Meet Panda, a bootleg cryptocurrency mining crew terrorizing organizations worldwide"},"content":{"rendered":"<p> [ad_1]<br \/>\n<\/p>\n<div>\n<p>Cybersecurity researchers have profiled a hacking crew named \u201cPanda\u201d believed to have amassed roughly $90,000 price of cryptocurrency by way of distant entry instruments (RATs) and illicit mining malware.<\/p>\n<p>The Cisco Talos Intelligence Group famous that whereas <em>Panda<\/em> isn\u2019t precisely subtle, it has continued as one of many web\u2019s most energetic attackers in recent times.<\/p>\n<p>Talos researchers highlighted\u00a0the group\u2019s willingness to constantly exploit susceptible internet purposes worldwide as key to its success. By October final 12 months, a configuration file featured in Panda malware had been downloaded greater than 300,000 instances.<\/p>\n<p>\u201cIn addition they often replace their focusing on, utilizing a wide range of exploits to focus on a number of vulnerabilities, and is fast to start out exploiting recognized vulnerabilities shortly after public POCs turn out to be obtainable, turning into a menace to anybody gradual to patch,\u201d stated the agency.<\/p>\n<h2>Panda has an enormous bag of RATs (and different exploits)<\/h2>\n<p><em>Panda<\/em>\u00a0was first detected in mid-2018 through the wildly profitable \u201cMassMiner\u201d marketing campaign. This was powered by a\u00a0worm which leveraged a number of in-built exploits, and even brute-forced entry to Microsoft SQL servers, to mine the choice cryptocurrency Monero (XMR).<\/p>\n<p>Now, Panda reportedly makes use of Mimikatz, an open-source program for stealing delicate info from compromised techniques, equivalent to usernames and passwords.<\/p>\n<figure class=\"post-image post-mediaBleed aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1242951 size-full lazy\" src=\"data:image\/gif;base64,R0lGODlhAQABAIAAAAAAAP\/\/\/yH5BAEAAAAALAAAAAABAAEAAAIBRAA7\" alt=\"\" width=\"640\" height=\"586\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" data-src=\"https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/09\/image4.png\" data-lazy=\"true\" data-srcset=\"https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/09\/image4.png 640w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/09\/image4-229x210.png 229w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/09\/image4-295x270.png 295w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/09\/image4-147x135.png 147w\"\/><figcaption><a href=\"#\" data-url=\"https:\/\/twitter.com\/intent\/tweet?url=https%3A%2F%2Fthenextweb.com%2Fhardfork%2F2019%2F09%2F18%2Fmeet-panda-an-illicit-cryptocurrency-mining-crew-terrorizing-organizations-worldwide%2F&amp;via=thenextweb&amp;related=thenextweb&amp;text=Check out this picture on: \u2026 and it\u2019s still evolving!\" data-title=\"Share \u2026 and it\u2019s still evolving! on Twitter\" data-width=\"685\" data-height=\"500\" class=\"post-image-share popitup\" title=\"Share \u2026 and it\u2019s still evolving! on Twitter\"><i class=\"icon icon--inline icon--twitter--dark\"\/><\/a>\u2026 and it\u2019s nonetheless evolving!<\/figcaption><\/figure>\n<p>Researchers additionally discovered Panda operates with exploits beforehand utilized by Shadow Brokers, a hacking crew that gained its popularity by publishing info taken from the US Nationwide Safety Company.<\/p>\n<p>Thus far, Talos has confirmed that Panda has hit organizations within the banking, transportation, telecommunications, IT companies, and healthcare industries.<\/p>\n<h2>This cryptocurrency mining crew could possibly be of Chinese language origin<\/h2>\n<p>Whoever is behind\u00a0<em>Panda<\/em>\u00a0doesn\u2019t actually care\u00a0<em>an excessive amount of<\/em> about operational safety. For instance, the group acquired its title as one associated area had been registered to a Chinese language-speaking actor who glided by the title \u201cPanda.\u201d<\/p>\n<p>An analyzed malware pattern additionally requested\u00a0knowledge utilizing an\u00a0IP geolocation service which offered the machine\u2019s IP handle and site in Chinese language.<\/p>\n<p>Much more curious, Talos analysts discovered Panda had been exploiting a vulnerability within the ThinkPHP internet framework to unfold its malware. Researchers report this software program is especially common in China.<\/p>\n<p>\u201cPanda\u2019s operational safety stays poor, with a lot of their outdated and present domains all hosted on the identical IP and their TTPs remaining comparatively related all through campaigns,\u201d wrote the agency. \u201cThe payloads themselves are additionally not very subtle.\u201d<\/p>\n<p>Nonetheless, Panda\u2019s efforts are stated generated round 1,215 XMR in earnings, which at the moment is price round $90,000\u00a0<span>\u2014<\/span> however the precise quantity earned depends on once they offered their cryptocurrency.<\/p>\n<p>That\u2019s one prolific hacking panda.<\/p>\n<p class=\"c-post-pubDate\">\n                                    Printed September 18, 2019 \u2014 12:12 UTC\n                                <\/p>\n<\/p><\/div>\n<p><script async src=\"http:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><script data-src=\"http:\/\/connect.facebook.net\/en_US\/sdk.js#xfbml=1&amp;appId=378011798897423&amp;version=v2.6\" id=\"socialSrcFacebook\" type=\"text\/template\"><\/script><br \/>\n<br \/>[ad_2]<br \/>\n<br \/><a href=\"https:\/\/thenextweb.com\/hardfork\/2019\/09\/18\/meet-panda-an-illicit-cryptocurrency-mining-crew-terrorizing-organizations-worldwide\/\">Supply hyperlink <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[ad_1] Cybersecurity researchers have profiled a hacking crew named \u201cPanda\u201d believed to have amassed roughly $90,000 price of cryptocurrency by way of distant entry instruments (RATs) and illicit mining malware. The Cisco Talos Intelligence Group famous that whereas Panda isn\u2019t precisely subtle, it has continued as one of many web\u2019s most energetic attackers in recent &hellip;<\/p>\n","protected":false},"author":1,"featured_media":171578,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-171576","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tie-world"],"_links":{"self":[{"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/posts\/171576","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/comments?post=171576"}],"version-history":[{"count":0,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/posts\/171576\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/media\/171578"}],"wp:attachment":[{"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/media?parent=171576"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/categories?post=171576"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/tags?post=171576"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}