News
RedTail cryptocurrency mining malware exploits Palo Alto Networks firewall vulnerability
May 30, 2024Press roomVulnerability/Cryptocurrency
The threat actors behind the Red tail Cryptocurrency mining malware has added to its arsenal of exploits with a recently disclosed security flaw affecting Palo Alto Networks’ firewalls.
According to findings from web security and infrastructure firm Akamai, the addition of the PAN-OS vulnerability to its toolkit has been complemented by updates to the malware, which now incorporates new anti-analysis techniques.
“Attackers have taken a step forward by employing private cryptocurrency mining pools for greater control over mining results despite increased operational and financial costs,” said security researchers Ryan Barnett, Stiv Kupchik and Maxim Zavodchik in a technician relationship shared with The Hacker News.
The infection sequence discovered by Akamai exploits a now-patched vulnerability in PAN-OS tracked as CVE-2024-3400 (CVSS Score: 10.0) which could allow an unauthenticated attacker to execute arbitrary code with root privileges on the firewall.
A successful exploitation is followed by the execution of commands designed to retrieve and execute a bash shell script from an external domain which, in turn, is responsible for downloading the RedTail payload based on the CPU architecture.
Other RedTail propagation mechanisms involve exploitation of known security flaws in TP-Link (CVE-2023-1389), ThinkPHP (CVE-2018-20062), Ivanti Connect Secure (CVE-2023-46805, and CVE-2024- 21887) and VMWare Workspace ONE Access and Identity Manager (CVE-2022-22954).
RedTail was first documented by security researcher Patryk Mahowiak in January 2024 in connection with a campaign that exploited the Log4Shell vulnerability (CVE-2021-44228) to distribute malware on Unix-based systems.
Then, in March 2024, Barracuda Networks disclosed details on cyber attacks exploiting flaws in SonicWall (CVE-2019-7481) and Visual Tools DVR (CVE-2021-42071) to install variants of the Mirai botnet, as well as shortcomings in ThinkPHP for deploying RedTail.
The latest version of the miner spotted in April packs significant updates as it includes an encrypted mining setup used to launch the built-in XMRig miner.
Another notable change is the absence of a cryptocurrency wallet, indicating that threat actors may have switched to a cryptocurrency wallet private mining pool or a proxy pool to gain financial benefits.
“The setup also shows that threat actors are trying to optimize the mining operation as much as possible, indicating a deep understanding of crypto-mining,” the researchers said.
“Unlike the previous RedTail variant reported in early 2024, this malware uses advanced evasion and persistence techniques. It forks multiple times to hinder analysis by debugging the process and kills any instance of [GNU Debugger] finds.”
Akamai described RedTail as having a high level of polish, something not commonly seen among cryptocurrency miner malware families out there.
“The investments required to run a private cryptocurrency mining operation are significant, including staff, infrastructure, and obfuscation,” the researchers concluded. “This sophistication could be indicative of a nation-state sponsored attack group.”
Did you find this article interesting? Follow us on Twitter AND LinkedIn to read the most exclusive content we publish.
Fuente
News
How Ether Spot ETF Approval Could Impact Crypto Prices: CNBC Crypto World
ShareShare article via FacebookShare article via TwitterShare article via LinkedInShare article via email
CNBC Crypto World features the latest news and daily trading updates from the digital currency markets and gives viewers a glimpse of what’s to come with high-profile interviews, explainers and unique stories from the ever-changing cryptocurrency industry. On today’s show, Ledn Chief Investment Officer John Glover weighs in on what’s driving cryptocurrency prices right now and how the potential approval of spot ether ETFs could impact markets.
News
Miners’ ‘Capitulation’ Signals Bitcoin Price May Have Bottomed Out: CryptoQuant
According to CryptoQuant, blockchain data shows signs that the Bitcoin mining industry is “capitulating,” a likely precursor to Bitcoin hitting a local price bottom before reaching new highs.
CryptoQuant analyzed metrics for miners, who are responsible for securing the Bitcoin network in exchange for newly minted BTC. As outlined in the market intelligence platform’s Wednesday report, multiple signs of capitulation have emerged over the past month, during which Bitcoin’s price has fallen 13% from $68,791 to $59,603.
One such sign includes a significant drop in Bitcoin’s hash rate, the total computing power that backs Bitcoin. After hitting a record high of 623 exashashes per second (EH/s) on April 27, the hash rate has fallen 7.7% to 576 EH/s, its lowest level in four months.
“Historically, extreme hash rate drawdowns have been associated with price bottoms,” CryptoQuant wrote. In particular, the 7.7% drawdown is reminiscent of an equivalent hash rate drawdown in December 2022, when Bitcoin’s price bottomed at $16,000 before rallying over 300% over the next 15 months.
This latest hash rate drop follows Bitcoin’s fourth cyclical “halving” event in April, which cut the number of coins paid out to miners in half. According to CryptoQuant’s Miner Profit/Loss Sustainability Indicator, this has left miners “mostly extremely underpaid” since April 20, forcing many to shut down mining machines that have now become unprofitable.
CrypotoQuant said that miners faced a 63% drop in daily revenue after the halving, when both Bitcoin block rewards and transaction fee revenues were much higher.
During this time, Bitcoin miners were seen moving coins from their on-chain wallets at a faster rate than usual, indicating that they may be selling their BTC reserves“Daily miner outflows reached their highest volume since May 21,” the company wrote.
Among the sales of Bitcoin miners, whales and national governmentsBitcoin’s price drop in June also hurt Bitcoin’s “hash price,” a metric of Bitcoin Miner Profitability per unit of computing power.
“Average mining revenue per hash (hash price) continues to hover near all-time lows,” CryptoQuant wrote. “Hashprice stands at $0.049 per EH/s, just above the all-time low hashprice of $0.045 reached on May 1st.”
By Ryan-Ozawa.
News
US Congressman French Hill Doubles Down on Trump’s Pro-Crypto Stance
US lawmaker French Hill has noted that Donald Trump will take a more pro-crypto approach than the current administration. The run-up to the presidential election has seen cryptocurrencies become an issue with lawmakers making huge statements ahead of the polls. Donald Trump has also been reaching out to the industry, making a pro-crypto case.
French Hill Backs Trump’s Pro-Crypto Stance
Republican Congressman French Hill has explained the type of cryptocurrency regulatory framework he believes Donald Trump could adopt in the country. In a recent interview with CNBC, French Hill said that the recently passed FIT21 bill is the type of regulatory framework the Trump administration will adopt in the sector.
#FIT21 passed the House with 71 Democratic votes, it’s exactly the kind of digital asset regulatory framework former President Trump would support if re-elected.
See more on @SquawkCNBC🔽 photo.twitter.com/ceTmU4LApU
— French Hill (@RepFrenchHill) July 3, 2024
THE FIT21 Bill It is intended to protect investors and consumers in the market by establishing clear rules and powers for the various regulators in the sector. According to Hill, Trump will adopt it because it directs the Securities and Exchange Commission (SEC) and the Commodity Futures Trading Commission (CFTC) on the specific regulatory framework needed in the market.
“… for people who are innovating and starting a crypto token, a related business, custody of those assets, how to ensure consumer protection, so I think that framework is the right approach and that’s what I’m going to recommend to the President to pass, which is that we have not passed it between now and the end of this Congress.”
He also called Trump an innovative and pro-growth president in financial matters.
Cryptocurrency is going mainstream
This election cycle saw the cryptocurrency industry taking a place in mainstream issues following broader adoption across demographics. From candidates moving toward enthusiasts to recent pro-Congress legislation, cryptocurrencies have become a rallying point for officials. The U.S. regulatory landscape has been criticized for stifling growth due to frequent SEC LawsuitsThis has led executives to push for pro-cryptocurrency laws and raise money for pro-industry candidates.
Read also: Federal Reserve Predicts “AI Will Be Deflationary” to Stimulate Economy
David is a financial news contributor with 4 years of experience in Blockchain and cryptocurrency. He is interested in learning about emerging technologies and has an eye for breaking news. Keeping up to date with trends, David has written in several niches including regulation, partnerships, cryptocurrency, stocks, NFTs, etc. Away from the financial markets, David enjoys cycling and horseback riding.
News
US Court Orders Sam Ikkurty to Pay $84 Million for Cryptocurrency Ponzi Scheme
A federal court has ordered Jafia LLC and its owner, Sam Ikkurty, to pay nearly $84 million to cryptocurrency investors after ruling that the company was operating a Ponzi scheme.
The ruling, issued by Judge Mary Rowland in the U.S. District Court for the Northern District of Illinois, follows a lawsuit filed by the Commodity Futures Trading Commission (CFTC) in 2022 after the fund collapsed.
Judge Rowland found that Ikkurty, based in Portland, Oregon, did numerous false claims on his company’s hedge funds.
These included misleading statements about his trading experience and the promise of high and stable profits. Instead, Ikkurty used funds from new investors to pay off previous investors, a hallmark of a Ponzi scheme.
The Ponzi Scheme
The court found that Ikkurty misappropriated investment funds for personal use without the knowledge of the investors. These funds were used for personal use and were reported as Fraudulent Investmentscausing significant financial losses to customers.
This non-transparent operation violated Transparency Commission regulations, which led to the imposition of a hefty fine to compensate defrauded investors and restore some public confidence in the financial system.
Judge Rowland emphasized that fraudulent activity such as this violates the law and undermines the integrity of modern financial markets. The $84 million award seeks to address the financial harm inflicted on investors and reinforce the importance of legal compliance in cryptocurrency trading.
-
Videos9 months ago
Bitcoin Price AFTER Halving REVEALED! What’s next?
-
Bitcoin8 months ago
Bitcoin Could Test Record Highs Next Week in ETF Flows, Says Analyst; Coinbase appears in the update
-
Videos9 months ago
Are cryptocurrencies in trouble? Bitcoin Insider Reveals “What’s Next?”
-
Videos9 months ago
Cryptocurrency Crash Caused by THIS…
-
Videos8 months ago
The REAL reason why cryptocurrency is going up!
-
Altcoin8 months ago
The best Altcoins to buy before they rise
-
Videos9 months ago
BlackRock Will Send Bitcoin to $116,000 in the Next 51 Days (XRP News)
-
Videos9 months ago
Donald Trump: I like Bitcoin now! Joe Biden HATES cryptocurrencies.
-
Videos8 months ago
Solana Cryptocurrencies: the future WILL SHOCK you | What comes next?
-
News9 months ago
TON, AKT, AR expect increases of 15%+ as the market stabilizes
-
Videos8 months ago
Bitcoin Whale REVEALS: The 5 Best Coins to Make You a Millionaire!
-
Videos8 months ago
BREAKING NEWS: The 19 best cryptocurrencies ready to skyrocket!