A Malware Found To Have Infected Computers, And Mined $2 Million In 3 Years

The trend of cryptojacking has faded in 2021. However, there is one undocumented Windows malware that is found to have infected over 222,000 systems worldwide since at least June 2018.

This malware has yielded its developer no less than 9,000 Moneros ($2 million) in illegal profits.

Called the 'Crackonosh', the malware is found to have been distributed through pirated copies of popular software on the internet.

When it is installed, it will disable antivirus programs in the machine, replace critical Windows system files such as serviceinstaller.msi and maintenance.vbs to cover its tracks, abuse the Windows Safe Mode, and to turn off automatic updates.

It will also install its own version of MSASCuiL.exe so victims won't suspect their Windows Defender is off.

It will then install a coin miner package called XMRig.

Monero mining

It's this miner package that will then exploit its host's resources to mine the cryptocurrency Monero, stealthily.

Researchers have found at least 30 different versions of the malware executable, discovered between January 1, 2018, and November 23, 2020, according to a blog post by Czech cybersecurity software company Avast.

The majority of people who are victims of this malware, reside in the U.S., Brazil, India, Poland, and the Philippines.

The finding of this malware, comes as a suspected Chinese threat actor behind DirtyMoe and Purple Fox malware were found to have compromised at least 100,000 Windows machines, as part of their evolving cryptojacking campaign dating all the way back to 2017.

"Crackonosh shows the risks in downloading cracked software," Avast security researcher Daniel Beneš said.

"As long as people continue to download cracked software, attacks like these will continue and continue to be profitable for attackers. The key take-away from this is that you really can't get something for nothing and when you try to steal software, odds are someone is trying to steal from you."