• Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
Friday, September 12, 2025
  • Login
  • Register
Coin24h.com
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
Coin24h.com
No Result
View All Result
Ledger Nano X - The secure hardware wallet
ADVERTISEMENT

Identification and Classification of Crypto-Malware Using ThreatMapper

9 December 2022
in Mining
Reading Time: 3 mins read
A A
0
Identification and Classification of Crypto-Malware Using ThreatMapper
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
cryptotrader
ADVERTISEMENT

Related articles

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024

Authors: Devi Prasad and Shyam Krishnaswamy

ThreatMapper, our open-source Cloud Native Application Protection Platform (CNAPP), now integrates natively with YaraHunter. YaraHunter is a powerful malware scanner for cloud-native – containers, images & hosts. In a previous post, we discussed scanning the cloud native assets for malware using YaraHunter – to identify and report possible indicators of malware across different cloud resources, pods, virtual machines, file systems, image registries, and build artifacts. In this post, we will discuss using ThreatMapper to classify various cloud-native malware, the enhancements to the Yara rulesets to identify crypto signature malware risks, and prioritize those risks using runtime context to build a better security posture.

Crypto malware attacks are becoming increasingly popular among cybercriminals due to the increase in value of the currency, and the widespread adoption. Once executed on the victim’s device, crypto-malware can typically run independently and indefinitely. As estimated by Google, a vast majority of instances (around 86%), in Google Cloud are compromised due to crypto mining. While not assuming devastating proportions like ransomware, crypto-malware still causes severe losses in terms of computation resources, leading to direct and indirect damages.

ThreatMapper is supported by a wide variety of Yara rule sets to classify malware. The Yara rule sets are descriptions of malware families based on textual or binary patterns. In particular, ThreatMapper has hundreds of rules that cover a wide range of classifications – Crypto Mining, DDOS, Information Stealing, Spam Bot, RootKit, KeyLoggers among others. In addition, host-based indicators like filenames, registry keys, exposed passwords, and secret keys also form an important part of the ruleset.

In our effort to keep ThreatMapper constantly abreast of the current set of challenges, we have recently included the rules for Cobalt strike malware. A brief background on Cobalt Strike – malicious actors leverage the vulnerability  CVE-2019-18935, a critical severity, that leads to remote code execution in the Telerik UI library and install Cobalt strike beacons. Once the beacons are installed, they are successful in mining Monero tokens by hijacking system resources. 

ThreatMapper, in addition to hundreds of existing rules that detect crypto miners, has also included the rules recently released by Google to detect Cobalt strike malware. This helps to detect the malware at all stages of the development and deployment lifecycle – as a part of CI/CD scans, from image repositories, or during the runtime of the containers, pods, and hosts in the infrastructure. 

The following is a sample result when scans are performed on images having Cobalt strike malware – 

Further, when XmRig crypto miner malware is present in an image, scanning those images produces results of the form –

XmRig crypto miner malware

ThreatMapper is also able to classify various malware types –

ThreatMapper classifies various malware types

In addition to classifying malware, the sensors deployed as a part of ThreatMapper provide useful runtime context, which is used to automatically prioritize the malware that needs immediate attention. In the upcoming days, we will add additional malware scan controls, rules, and insights derived from the various malware classifications. If you are interested in taking a deeper look at the technical integration, take a look at our ThreatMapper repository. We welcome contributions of all forms, including documentation, feature requests, technical bugs, or source code patches.

The post Identification and Classification of Crypto-Malware Using ThreatMapper appeared first on Deepfence.

*** This is a Security Bloggers Network syndicated blog from Deepfence authored by Shyam Krishnaswamy. Read the original post at: https://deepfence.io/crypto-malware-threatmapper/

Source link

Cryptohopper
ADVERTISEMENT
[crypto-donation-box]
Tags: ClassificationCryptoMalwareIdentificationThreatMapper
Share76Tweet47
Ledger Nano X - The secure hardware wallet
Previous Post

XRP Remains in Uptrend Despite Flurry of Enormous Transactions in Last 2 Days: Crypto Market Review, Dec. 8 – U.Today

Next Post

‘Wolf of Wall Street’ Jordan Belfort Expects Bitcoin and Ethereum to Be ‘Substantially Higher’ Despite FTX Collapse – Markets and Prices Bitcoin News

Related Posts

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
0

A fake news story circulated today about Russia’s supposed embrace of bitcoin mining and crypto payments. According to excited social...

New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024
0

A new report estimates a $20 billion revenue opportunity in Bitcoin BTC/USD mining chips and hardware over the next five...

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

30 July 2024
0

(Bloomberg) -- Russia is moving to regulate the use of cryptocurrencies, as companies wrestle with increasing difficulties in foreign payments...

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

30 July 2024
0

The Russian central bank plans to initiate international payments in cryptocurrencies by the end of the year to overcome delays...

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

30 July 2024
0

Listed both on Wall Street and the London Stock Exchange (LSE) Bitcoin miner Argo Blockchain, has announced a £6.5 million...

Load More
Next Post
‘Wolf of Wall Street’ Jordan Belfort Expects Bitcoin and Ethereum to Be ‘Substantially Higher’ Despite FTX Collapse – Markets and Prices Bitcoin News

'Wolf of Wall Street' Jordan Belfort Expects Bitcoin and Ethereum to Be 'Substantially Higher' Despite FTX Collapse – Markets and Prices Bitcoin News

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Plugin Install : Widget Tab Post needs JNews - View Counter to be installed
  • Trending
  • Comments
  • Latest
Dennis Potter Defends Bitcoin’s Low Fees Amid Security Concerns

Dennis Potter Defends Bitcoin’s Low Fees Amid Security Concerns

12 September 2025
Galaxy Digital Buys 2.31 Million Solana Tokens Worth Nearly 6 Million – Yahoo Finance

Galaxy Digital Buys 2.31 Million Solana Tokens Worth Nearly $536 Million – Yahoo Finance

12 September 2025
4 Key Signs Altcoin Season Is Accelerating Fast in September 2025

4 Key Signs Altcoin Season Is Accelerating Fast in September 2025

12 September 2025
BitMine’s Ethereum Holdings Top 2.1 Million After Fresh 46,255 ETH Buy

BitMine’s Ethereum Holdings Top 2.1 Million After Fresh 46,255 ETH Buy

12 September 2025

About Us

We publish a comprehensive news feed covering all news relevant to the crypto user, covering main industry news, politics and regulation as well as consumer-level “news you can use” (practical stuff), including handy DIY tips, links to useful tools, unbiased reviews and opinions revolving around cryptocurrency. Simple logic and real-world examples are preferred before technical jargon and personal rants.

Categories

  • Altcoin
  • ApeCoin
  • Bitcoin
  • Blockchain
  • BNB
  • Cardano
  • Cryptocurrency
  • DOGE
  • DOT
  • Ethereum
  • HBAR
  • Litecoin
  • Market
  • Meta News
  • Mining
  • NFT
  • QNT
  • Regulation
  • SHIBA
  • Solano
  • Tether
  • Uncategorized
  • XDC
  • XLM
  • XRP

What’s New Here!

  • Dennis Potter Defends Bitcoin’s Low Fees Amid Security Concerns
  • Galaxy Digital Buys 2.31 Million Solana Tokens Worth Nearly $536 Million – Yahoo Finance
  • 4 Key Signs Altcoin Season Is Accelerating Fast in September 2025
  • BitMine’s Ethereum Holdings Top 2.1 Million After Fresh 46,255 ETH Buy
  • FTX, Alameda Redeem $45 Million in Solana From Staking – Cryptonews

Subscribe Now

Our Partner

Round Main Logo
  • About Us
  • Privacy Policy
  • Contact Us

© 2022-2025 coin24h.com

No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining

© 2020 coin24h.com

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • bitcoinBitcoin (BTC) $ 115,141.00
  • ethereumEthereum (ETH) $ 4,524.02
  • xrpXRP (XRP) $ 3.05
  • tetherTether (USDT) $ 1.00
  • solanaSolana (SOL) $ 238.13
  • bnbBNB (BNB) $ 906.65
  • usd-coinUSDC (USDC) $ 0.999806
  • dogecoinDogecoin (DOGE) $ 0.259933
  • staked-etherLido Staked Ether (STETH) $ 4,516.60
  • tronTRON (TRX) $ 0.348387
  • cardanoCardano (ADA) $ 0.895298
  • wrapped-stethWrapped stETH (WSTETH) $ 5,481.30
  • chainlinkChainlink (LINK) $ 24.44
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,877.31
  • hyperliquidHyperliquid (HYPE) $ 56.37
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 114,898.00
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • suiSui (SUI) $ 3.68
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • stellarStellar (XLM) $ 0.394155
  • wrapped-eethWrapped eETH (WEETH) $ 4,861.11
  • avalanche-2Avalanche (AVAX) $ 28.58
  • bitcoin-cashBitcoin Cash (BCH) $ 591.61
  • wethWETH (WETH) $ 4,523.12
  • hedera-hashgraphHedera (HBAR) $ 0.241091
  • leo-tokenLEO Token (LEO) $ 9.60
  • litecoinLitecoin (LTC) $ 115.62
  • crypto-com-chainCronos (CRO) $ 0.256166
  • the-open-networkToncoin (TON) $ 3.19
  • usdsUSDS (USDS) $ 0.999334
  • shiba-inuShiba Inu (SHIB) $ 0.000013
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 115,086.00
  • polkadotPolkadot (DOT) $ 4.21
  • whitebitWhiteBIT Coin (WBT) $ 43.73
  • uniswapUniswap (UNI) $ 10.05
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.200333
  • ethenaEthena (ENA) $ 0.768403
  • mantleMantle (MNT) $ 1.58
  • moneroMonero (XMR) $ 276.03
  • aaveAave (AAVE) $ 310.62
  • bitget-tokenBitget Token (BGB) $ 4.91
  • daiDai (DAI) $ 1.00
  • pepePepe (PEPE) $ 0.000011
  • okbOKB (OKB) $ 190.81
  • memecoreMemeCore (M) $ 2.11
  • jito-staked-solJito Staked SOL (JITOSOL) $ 292.52
  • ondo-financeOndo (ONDO) $ 1.09
  • nearNEAR Protocol (NEAR) $ 2.73