Connect with us

News

RedTail cryptocurrency mining malware exploits Palo Alto Networks firewall vulnerability

AltcoinUpdates Staff

Published

on

Palo Alto Networks Firewall Vulnerability

May 30, 2024Press roomVulnerability/Cryptocurrency

The threat actors behind the Red tail Cryptocurrency mining malware has added to its arsenal of exploits with a recently disclosed security flaw affecting Palo Alto Networks’ firewalls.

According to findings from web security and infrastructure firm Akamai, the addition of the PAN-OS vulnerability to its toolkit has been complemented by updates to the malware, which now incorporates new anti-analysis techniques.

“Attackers have taken a step forward by employing private cryptocurrency mining pools for greater control over mining results despite increased operational and financial costs,” said security researchers Ryan Barnett, Stiv Kupchik and Maxim Zavodchik in a technician relationship shared with The Hacker News.

The infection sequence discovered by Akamai exploits a now-patched vulnerability in PAN-OS tracked as CVE-2024-3400 (CVSS Score: 10.0) which could allow an unauthenticated attacker to execute arbitrary code with root privileges on the firewall.

Cyber ​​security

A successful exploitation is followed by the execution of commands designed to retrieve and execute a bash shell script from an external domain which, in turn, is responsible for downloading the RedTail payload based on the CPU architecture.

Other RedTail propagation mechanisms involve exploitation of known security flaws in TP-Link (CVE-2023-1389), ThinkPHP (CVE-2018-20062), Ivanti Connect Secure (CVE-2023-46805, and CVE-2024- 21887) and VMWare Workspace ONE Access and Identity Manager (CVE-2022-22954).

RedTail was first documented by security researcher Patryk Mahowiak in January 2024 in connection with a campaign that exploited the Log4Shell vulnerability (CVE-2021-44228) to distribute malware on Unix-based systems.

RedTail cryptocurrency mining malware

Then, in March 2024, Barracuda Networks disclosed details on cyber attacks exploiting flaws in SonicWall (CVE-2019-7481) and Visual Tools DVR (CVE-2021-42071) to install variants of the Mirai botnet, as well as shortcomings in ThinkPHP for deploying RedTail.

The latest version of the miner spotted in April packs significant updates as it includes an encrypted mining setup used to launch the built-in XMRig miner.

Another notable change is the absence of a cryptocurrency wallet, indicating that threat actors may have switched to a cryptocurrency wallet private mining pool or a proxy pool to gain financial benefits.

Cyber ​​security

“The setup also shows that threat actors are trying to optimize the mining operation as much as possible, indicating a deep understanding of crypto-mining,” the researchers said.

“Unlike the previous RedTail variant reported in early 2024, this malware uses advanced evasion and persistence techniques. It forks multiple times to hinder analysis by debugging the process and kills any instance of [GNU Debugger] finds.”

Akamai described RedTail as having a high level of polish, something not commonly seen among cryptocurrency miner malware families out there.

“The investments required to run a private cryptocurrency mining operation are significant, including staff, infrastructure, and obfuscation,” the researchers concluded. “This sophistication could be indicative of a nation-state sponsored attack group.”

Did you find this article interesting? Follow us on Twitter AND LinkedIn to read the most exclusive content we publish.


Fuente

We are the editorial team of Altcoin Updates, where seriousness meets clarity in cryptocurrency analysis. With a robust team of finance and blockchain technology experts, we are dedicated to meticulously exploring complex crypto markets with detailed assessments and an unbiased approach. Our mission is to democratize access to knowledge of emerging financial technologies, ensuring they are understandable and accessible to all. In every article on Altcoin Updates, we strive to provide content that not only educates, but also empowers our readers, facilitating their integration into the financial digital age.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Información básica sobre protección de datos Ver más

  • Responsable: Miguel Mamador.
  • Finalidad:  Moderar los comentarios.
  • Legitimación:  Por consentimiento del interesado.
  • Destinatarios y encargados de tratamiento:  No se ceden o comunican datos a terceros para prestar este servicio. El Titular ha contratado los servicios de alojamiento web a Banahosting que actúa como encargado de tratamiento.
  • Derechos: Acceder, rectificar y suprimir los datos.
  • Información Adicional: Puede consultar la información detallada en la Política de Privacidad.

News

How Ether Spot ETF Approval Could Impact Crypto Prices: CNBC Crypto World

AltcoinUpdates Staff

Published

on

How Ether Spot ETF Approval Could Impact Crypto Prices: CNBC Crypto World

ShareShare article via FacebookShare article via TwitterShare article via LinkedInShare article via email

CNBC Crypto World features the latest news and daily trading updates from the digital currency markets and gives viewers a glimpse of what’s to come with high-profile interviews, explainers and unique stories from the ever-changing cryptocurrency industry. On today’s show, Ledn Chief Investment Officer John Glover weighs in on what’s driving cryptocurrency prices right now and how the potential approval of spot ether ETFs could impact markets.

Fuente

Continue Reading

News

Miners’ ‘Capitulation’ Signals Bitcoin Price May Have Bottomed Out: CryptoQuant

AltcoinUpdates Staff

Published

on

Miners' 'Capitulation' Signals Bitcoin Price May Have Bottomed Out: CryptoQuant

According to CryptoQuant, blockchain data shows signs that the Bitcoin mining industry is “capitulating,” a likely precursor to Bitcoin hitting a local price bottom before reaching new highs.

CryptoQuant analyzed metrics for miners, who are responsible for securing the Bitcoin network in exchange for newly minted BTC. As outlined in the market intelligence platform’s Wednesday report, multiple signs of capitulation have emerged over the past month, during which Bitcoin’s price has fallen 13% from $68,791 to $59,603.

One such sign includes a significant drop in Bitcoin’s hash rate, the total computing power that backs Bitcoin. After hitting a record high of 623 exashashes per second (EH/s) on April 27, the hash rate has fallen 7.7% to 576 EH/s, its lowest level in four months.

“Historically, extreme hash rate drawdowns have been associated with price bottoms,” CryptoQuant wrote. In particular, the 7.7% drawdown is reminiscent of an equivalent hash rate drawdown in December 2022, when Bitcoin’s price bottomed at $16,000 before rallying over 300% over the next 15 months.

This latest hash rate drop follows Bitcoin’s fourth cyclical “halving” event in April, which cut the number of coins paid out to miners in half. According to CryptoQuant’s Miner Profit/Loss Sustainability Indicator, this has left miners “mostly extremely underpaid” since April 20, forcing many to shut down mining machines that have now become unprofitable.

CrypotoQuant said that miners faced a 63% drop in daily revenue after the halving, when both Bitcoin block rewards and transaction fee revenues were much higher.

During this time, Bitcoin miners were seen moving coins from their on-chain wallets at a faster rate than usual, indicating that they may be selling their BTC reserves“Daily miner outflows reached their highest volume since May 21,” the company wrote.

Among the sales of Bitcoin miners, whales and national governmentsBitcoin’s price drop in June also hurt Bitcoin’s “hash price,” a metric of Bitcoin Miner Profitability per unit of computing power.

“Average mining revenue per hash (hash price) continues to hover near all-time lows,” CryptoQuant wrote. “Hashprice stands at $0.049 per EH/s, just above the all-time low hashprice of $0.045 reached on May 1st.”

By Ryan-Ozawa.

Fuente

Continue Reading

News

US Congressman French Hill Doubles Down on Trump’s Pro-Crypto Stance

AltcoinUpdates Staff

Published

on

US Congressman French Hill Doubles Down on Trump's Pro-Crypto Stance

US lawmaker French Hill has noted that Donald Trump will take a more pro-crypto approach than the current administration. The run-up to the presidential election has seen cryptocurrencies become an issue with lawmakers making huge statements ahead of the polls. Donald Trump has also been reaching out to the industry, making a pro-crypto case.

French Hill Backs Trump’s Pro-Crypto Stance

Republican Congressman French Hill has explained the type of cryptocurrency regulatory framework he believes Donald Trump could adopt in the country. In a recent interview with CNBC, French Hill said that the recently passed FIT21 bill is the type of regulatory framework the Trump administration will adopt in the sector.

THE FIT21 Bill It is intended to protect investors and consumers in the market by establishing clear rules and powers for the various regulators in the sector. According to Hill, Trump will adopt it because it directs the Securities and Exchange Commission (SEC) and the Commodity Futures Trading Commission (CFTC) on the specific regulatory framework needed in the market.

“… for people who are innovating and starting a crypto token, a related business, custody of those assets, how to ensure consumer protection, so I think that framework is the right approach and that’s what I’m going to recommend to the President to pass, which is that we have not passed it between now and the end of this Congress.”

He also called Trump an innovative and pro-growth president in financial matters.

Cryptocurrency is going mainstream

This election cycle saw the cryptocurrency industry taking a place in mainstream issues following broader adoption across demographics. From candidates moving toward enthusiasts to recent pro-Congress legislation, cryptocurrencies have become a rallying point for officials. The U.S. regulatory landscape has been criticized for stifling growth due to frequent SEC LawsuitsThis has led executives to push for pro-cryptocurrency laws and raise money for pro-industry candidates.

Read also: Federal Reserve Predicts “AI Will Be Deflationary” to Stimulate Economy

David Pokima

David is a financial news contributor with 4 years of experience in Blockchain and cryptocurrency. He is interested in learning about emerging technologies and has an eye for breaking news. Keeping up to date with trends, David has written in several niches including regulation, partnerships, cryptocurrency, stocks, NFTs, etc. Away from the financial markets, David enjoys cycling and horseback riding.



Fuente

Continue Reading

News

US Court Orders Sam Ikkurty to Pay $84 Million for Cryptocurrency Ponzi Scheme

AltcoinUpdates Staff

Published

on

U.S. Court orders Sam Ikkurty to pay $84M for crypto Ponzi scheme

A federal court has ordered Jafia LLC and its owner, Sam Ikkurty, to pay nearly $84 million to cryptocurrency investors after ruling that the company was operating a Ponzi scheme.

The ruling, issued by Judge Mary Rowland in the U.S. District Court for the Northern District of Illinois, follows a lawsuit filed by the Commodity Futures Trading Commission (CFTC) in 2022 after the fund collapsed.

Judge Rowland found that Ikkurty, based in Portland, Oregon, did numerous false claims on his company’s hedge funds.

These included misleading statements about his trading experience and the promise of high and stable profits. Instead, Ikkurty used funds from new investors to pay off previous investors, a hallmark of a Ponzi scheme.

The Ponzi Scheme

The court found that Ikkurty misappropriated investment funds for personal use without the knowledge of the investors. These funds were used for personal use and were reported as Fraudulent Investmentscausing significant financial losses to customers.

This non-transparent operation violated Transparency Commission regulations, which led to the imposition of a hefty fine to compensate defrauded investors and restore some public confidence in the financial system.

Judge Rowland emphasized that fraudulent activity such as this violates the law and undermines the integrity of modern financial markets. The $84 million award seeks to address the financial harm inflicted on investors and reinforce the importance of legal compliance in cryptocurrency trading.

Fuente

Continue Reading

Trending

Copyright © 2024 ALTCOINUPDATES.XYZ All rights reserved. This website provides educational content and highlights that investing involves risks. It is essential to conduct thorough research before investing and to be prepared to assume potential losses. Be sure to fully understand the risks involved before making investment decisions. Important: We do not provide financial or investment advice. All content is presented for educational purposes only.