Categories: NewsSecurity

Bondnet Botnet Hijacks Windows Server Machines to Mine Monero and ZCash

It was only a matter of time until a new botnet would start making the rounds. It appears this new type of malware originates from China, albeit that has not been officially confirmed at this stage. So far, the botnet is comprised of 15,000 infected Windows Server machines, all of which are mining cryptocurrencies. Interestingly enough, the primarily mined cryptocurrency is Monero, and not Bitcoin.

Crypto-mining Botnet Has Grown More Powerful

It is always quite interesting to take note of new malware types designed to mine cryptocurrencies. Over the past few years, the world has seen multiple iterations of such malware. In most cases, these nefarious tools

hijack computers to mine Bitcoin or even Dogecoin. However, that situation has come to change thanks to this newly discovered botnet.

To be more specific, the Bondnet botnet is capable of infecting any machine running the Windows Server operating system. It was first spotted back in December of 2016 when it had seemingly enslaved a handful of machines. That number has now grown to 15,000 controlled machines, all of which are used to mine a wide variety of popular cryptocurrencies. First and foremost, the infected machine will try to mine Monero, a cryptocurrency focusing on privacy and anonymous transactions.

However, it appears this malware can mine other cryptocurrencies as well. Interestingly enough, the developer of Bondnet has no interest in mining Bitcoin, Ethereum, or Litecoin right now. Instead, they opt to mine ByteCoin, RieCoin, and ZCash. These are quite interesting choices, although the hardware they hijack lends itself to profitably mining these coins over time. With 15,000 machines under the criminals’ control, they can mine a respectable amount of cryptocurrency at no additional cost.

Related Post

This particular botnet has grown exponentially thanks to a time-consuming process. The developer relies on different techniques to infect machines all over the world. It is possible a combination of brute-force attacks and weak RDP credentials is the main source of distribution at this stage. Additionally, a lot of Windows Server-based machines run other server software, which can be exploited, including MSSQL, Apache Tomcat, and phpMyAdmin.

As one would somewhat expect, once the assailant gains access to the computer, he uses a Remote Access Trojan to control the machine moving forward. Installing a cryptocurrency-related miner becomes a trivial matter at that point. Over half of the infected machines run Windows Server 2008 R2, although a good portion runs Windows Server 2012 R2. It is evident nearly all popular versions of this operating system are prone to getting hijacked.

What is rather intriguing is how this botnet seems to gain and lose new bots every single day. The growth has all but stagnated, yet it remains a big threat until the matter can be properly resolved. Server administrators will need to step up their security game to prevent servers from getting hijacked for cryptocurrency mining purposes. Luckily, a detection and cleanup utility has been

released by security firm GuardiCore.

If you liked this article, follow us on Twitter @themerklenews and make sure to subscribe to our newsletter to receive the latest bitcoin, cryptocurrency, and technology news.

JP Buntinx

JP Buntinx is a FinTech and Bitcoin enthusiast living in Belgium. His passion for finance and technology made him one of the world's leading freelance Bitcoin writers, and he aims to achieve the same level of respect in the FinTech sector.

Share
Published by
JP Buntinx

Recent Posts

Best Altcoins to Invest in Today: Qubetics Sets the Stage for Blockchain’s Future as Bitcoin Hits $108K and Litecoin Soars

The cryptocurrency world has always been a hotbed of innovation, attracting both seasoned investors and…

8 hours ago

Dogecoin Millionaire Predicts This Undervalued Altcoin Could Match DOGE’s 2021 Gains

Dogecoin's 2021 rally was a historic one, turning ordinary investors into overnight millionaires. This magnificent…

8 hours ago

Qubetics Presale Skyrockets to $7.5M as XRP and Arbitrum Lead Best Altcoins for Exponential Returns

The crypto market is always evolving, with big names like Bitcoin and Ethereum leading the…

9 hours ago

Over 300K Users Actively Mine Crypto On BlockDAG’s X1 Miner App While BNB Bulls Eye $3K; What’s XRP’s Price Target?

The crypto market is ablaze with excitement as altcoins like XRP and BNB make major…

9 hours ago

Best Crypto Presale To Buy Now: Rollblock Delivers For Holders With New License, Record Sign Ups and 7000+ Games

Rollblock is quickly becoming the best crypto presale to buy, delivering unmatched value for its…

13 hours ago

Polkadot And Uniswap Gearing For Post-Christmas Jump As Rollblock Raises $7.4 Million in Presale

While Rollblock's continues its crypto presale, with its value increasing regularly, Polkadot (DOT) and Uniswap…

13 hours ago