Crypto mining malware impersonates Google translate desktop, other legitimate apps


Israeli-based cyber threat intelligence firm, Check Point Research (CPR) unmasked a malicious crypto mining malware campaign dubbed Nitrokod as the perpetrator behind the infection of thousands of machines across 11 countries in a report published on Sunday.

Crypto miner malware, also known as cryptojackers, is a type of malware that exploits the computing power of infected PCs to mine cryptocurrency.

Nitrokod has been impersonating Google Translate Desktop and other free software on websites to launch crypto miner malware and infect PCs.  When unsuspecting users search for “Google Translate Desktop download”, the malicious link to the malware-infected software appears at the top of Google Search results.

Since 2019, the malware has been operating with a multi-stage infection process, starting off by delaying contaminating the infection process until a few weeks after the users download the malicious link. They also remove traces of the original installation, keeping the malware-free from detection by anti-virus programs.

“Once the user launches the new software, an actual Google Translate application is installed,” the CPR report read. This is where victims encounter realistic-looking programs with a Chromium-based framework that directs the user from the Google Translate webpage and tricks them into downloading the fake application.

In the next stage, the malware schedules tasks to clear logs to remove related files and evidence and the next stage of the infection chain will continue after 15 days multi-stage approach helps the malware avoid being detected in a sandbox set up by security researchers.

“In addition, an updated file is dropped, which starts a series of four droppers until the actual malware is dropped,” the CPR report added.

In other words, the malware starts a Monero (XMR) crypto-mining operation whereby the malware “powermanager.exe” is stealthily dropped into the infected machines by connecting to its Command and Control server that enables cybercriminals to monetize users of  Google Translate’s desktop app.

Monero is the best-known cryptocurrency for cryptojackers and other illicit transactions. The cryptocurrency offers near anonymity for its holders.

It is easy to fall victim to crypto miner malware since they are dropped from software found on the top of Google search results for legitimized applications. If you suspect your PC is infected, details on how to recover your infected machine can be found at the end of the CPR report. 



Source link

Related articles

China to purchase 200 Boeing jets and ease uncommon earth curbs in US commerce breakthrough

China introduced it'll buy 200 Boeing jets, evaluate uncommon earth export licences for civilian use and pursue reciprocal tariff cuts on $30 billion or extra of products with the US as a part...

Bitcoin Value Stabilizes Above $76K, Merchants Await Subsequent Main Transfer

Bitcoin worth began a contemporary decline under the $76,800 zone. BTC is consolidating and may battle to remain above the $76,000 help. Bitcoin failed to remain above $77,000 and prolonged losses. The worth is buying...

The True Motive Your Oven Has a Backside Drawer (It is Not What You Suppose)

Most of us deal with the area beneath the oven as a handy hiding spot for the cookie sheets and muffin tins we solely use yearly. It is the final word kitchen junk...

Wintermute-Linked Wallets Obtain 500 BTC Value $38M From Decade-Previous Bitcoin Holder

Key TakeawaysWintermute-linked wallets acquired 500 BTC value $38M after a 10-year dormancy interval.Arkham Intelligence information flagged hyperlinks between Wintermute transfers and a Binance deposit pockets.Bitcoin at $382 in Jan. 2016 turned 500 BTC...

S&P 500 Momentum Indicators a Rally That May Lengthen Into Mid-July

The underside window is the day by day and prime window is the NYSE McClellan Oscillator. Market bottoms are made when a “Promoting Climax” is generated and proper after a “Signal of...
spot_img

Latest articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

WP2Social Auto Publish Powered By : XYZScripts.com