• Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
Friday, July 11, 2025
  • Login
  • Register
Coin24h.com
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
Coin24h.com
No Result
View All Result
Ledger Nano X - The secure hardware wallet
ADVERTISEMENT

RedTail Malware Abuses Palo Alto Flaw in Latest Cryptomining Campaign

30 May 2024
in Mining
Reading Time: 4 mins read
A A
0
RedTail Malware Abuses Palo Alto Flaw in Latest Cryptomining Campaign
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
cryptotrader
ADVERTISEMENT

Related articles

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024

Hackers with possible ties to the notorious North Korea-linked Lazarus Group are exploiting a recent critical vulnerability in Palo Alto Network’s PAN-OS software to run a sophisticated cryptomining operation that likely has nation-state backing.

In a report Thursday, threat researchers with Akamai said the bad actors behind this variant of the RedTail cryptomining malware are changing tactics, incorporating the PAN-OS flaw – tracked as CVE-2024-3400 – as well as using advanced evasion and persistence techniques and their own mining pools rather than public crypto wallets.

Some of the techniques mirror those used by the Lazarus Group – something that other researchers have suggested – and display a level of complexity and cost that suggest a nation-state like North Korea is behind the cryptomining campaign.

“There are many glossy cryptominers out there, but seeing one with this level of polish is uncommon,” Akamai security researchers Ryan Barnett, Stiv Kupchik, and Maxim Zavodchik wrote in the report. “The investments required to run a private cryptomining operation are significant, including staffing, infrastructure, and obfuscation. This sophistication may be indicative of a nation-state–sponsored attack group.

They added that “for any business, there is ongoing testing and evolution to ensure that the product (in this case, malware) is successful, which is unlikely to be done without some type of substantial financial backing. The malware was likely quite profitable if it garnered this degree of attention from a sophisticated group.”

RedTail Hit the Scene Months Ago

The RedTail cryptominer was first detected in December 2023 by researchers with Cyber Security Associates, who published a detailed report about it the following month. At the time, it was seen abusing the infamous Log4j vulnerability to mine Monero cryptocurrency using the same commands that the Akamai researchers wrote they found in the latest campaign.

A Lazarus advanced persistent threat (APT) subgroup called Andariel was detected late last year by Cisco’s Talos group running a campaign that exploited the Log4j flaw.

However, targeting the Palo Alto vulnerability to launch the operation is new, Barnett, Kupchik, and Zavodchik wrote. The cryptomining group behind the latest RedTail campaign in the past had targeted flaws found in TP-Link Router (CVE-2023-01389), VMware’s Workspace ONE Access and Identity Manager (CVE-2022-22954), ThinkPHO file inclusion and remote code execution (RCE) through pearcmd (no CVE), and ThinkPHP RCE (CVE-2018-20062).

The list also includes two bugs – CVE-2023-46805 and CVE-2024-21887 – in Ivanti’s SecureConnect, one of several of the software company’s products that have been hampered in recent months by vulnerabilities. Cybersecurity firm GrayNoise detected the abuse of the Ivanti flaws in cryptomining campaigns in January.

Group Abuses a PAN-OS Flaw

Palo Alto disclosed the PAN-OS zero-day vulnerability in an advisory April 11 that had been exploited by a threat group identified as UTA0218 to export device configuration data and to use it as an entry point into victims’ networks, according to report by Veloxity researchers that month.

The Akamai researchers wrote that the Palo Alto flaw “allows an attacker to create an arbitrary file that could eventually enable command execution with root user privileges. Specifically, by setting a particular value in the SESSID cookie, PAN-OS is manipulated into creating a file named after this value. When combined with a path traversal technique, this allows the attacker to control both the filename and the directory in which the file is stored.”

The specific malware servers that served the RedTail variant they tracked were active between early April and the beginning of this month, with the exploitation of the PAN-OS bug beginning at least April 21.

The researchers said initial research into the RedTail malware found that it could be used for distributed denial-of-service (DDoS) and cryptomining campaigns, then determine cryptomining was the bad actor’s goal. It’s a variant of XMRig – a legitimate cryptomining tool that often is used by cybercriminals – though there were significant differences from previous RedTail versions. The malware’s infrastructure uses multiple unrelated servers that are hosted by legitimate hosting companies.

“The malware did not make any ‘home calls’ to retrieve the mining configuration,” Barnett, Kupchik, and Zavodchik wrote. “Instead, the threat actors embedded XMRig’s code into their own code and added their own logic before and after it.”

New Modifications

Among the modifications was an encrypted mining configuration that the malware eventually decrypts before handing control over to the XMRig code. The threat actors also didn’t use a public crypto wallet, suggesting they opted to run their own mining pools or pool proxies, suggested a sophisticated operation in which they wanted greater control of the mining outcomes even those it meant increased operation and financial costs that come with running a private server.

“The configuration also shows that the threat actors are trying to optimize the mining operation as much as possible, indicating a deep understanding of cryptomining,” the researchers wrote. “Unlike the previous RedTail variant reported in early 2024, this malware employs advanced evasion and persistence techniques. It forks itself multiple times to hinder analysis by debugging its process and kills any instance of GDB it finds. To maintain persistence, the malware also adds a cron job to survive a system reboot.”

Money is the Goal

By exploiting the VMware and other flaws, the RedTail bad actors target Internet of Things (IoT) devices, web applications, SSL-VPNs, and security devices, such as Ivanti’s Connect Secure and Palo Alto’s GlobalProtect.

“Though one might assume that the threat actors who are exploiting SSL-VPNs and security devices … are primarily focused on gaining access to the internal network of an organization, these same vulnerabilities can also provide additional revenue streams for the attackers, including state sponsored actors,” they wrote.

That would be in line with North Korea, which runs cyberattacks to steal information and to fund it nuclear and ballistic missile operations. Reuters reported in February that United Nations investigators were looking at 58 cryptocurrency-related cyberattacks on companies by North Korea that brought in $3 billion that the country used for its weapons programs.

Recent Articles By Author

Source link

Cryptohopper
ADVERTISEMENT
[crypto-donation-box]
Tags: AbusesaltocampaignCryptoMiningFlawLatestMalwarePaloRedTail
Share76Tweet47
Ledger Nano X - The secure hardware wallet
Previous Post

Ether (ETH) Spot ETFs to See Much Lower Demand Than Bitcoin (BTC) Equivalents, JPMorgan (JPM) Says

Next Post

Dogecoin Dog Kabosu To Be Subject Of Doc From ‘Queer Eye’ Producer Scout

Related Posts

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
0

A fake news story circulated today about Russia’s supposed embrace of bitcoin mining and crypto payments. According to excited social...

New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024
0

A new report estimates a $20 billion revenue opportunity in Bitcoin BTC/USD mining chips and hardware over the next five...

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

30 July 2024
0

(Bloomberg) -- Russia is moving to regulate the use of cryptocurrencies, as companies wrestle with increasing difficulties in foreign payments...

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

30 July 2024
0

The Russian central bank plans to initiate international payments in cryptocurrencies by the end of the year to overcome delays...

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

30 July 2024
0

Listed both on Wall Street and the London Stock Exchange (LSE) Bitcoin miner Argo Blockchain, has announced a £6.5 million...

Load More
Next Post
Dogecoin Dog Kabosu To Be Subject Of Doc From ‘Queer Eye’ Producer Scout

Dogecoin Dog Kabosu To Be Subject Of Doc From ‘Queer Eye’ Producer Scout

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Plugin Install : Widget Tab Post needs JNews - View Counter to be installed
  • Trending
  • Comments
  • Latest
BNB Price Climbs Toward 3 as Volume and Whale Demand Increase – Brave New Coin

BNB Price Climbs Toward $733 as Volume and Whale Demand Increase – Brave New Coin

11 July 2025
Rising Bets On Ethereum: Futures Open Interest Jumps To Fresh Multi-Month High

Rising Bets On Ethereum: Futures Open Interest Jumps To Fresh Multi-Month High

10 July 2025
Pump.fun makes first acquisition, purchases Solana-based copy-trading wallet tracker Kolscan – The Block

Pump.fun makes first acquisition, purchases Solana-based copy-trading wallet tracker Kolscan – The Block

10 July 2025
ChatGPT's 42-Signal BNB Analysis Flags 0 Breakout Amid Corporate Treasury Revolution – Cryptonews

ChatGPT's 42-Signal BNB Analysis Flags $670 Breakout Amid Corporate Treasury Revolution – Cryptonews

10 July 2025

About Us

We publish a comprehensive news feed covering all news relevant to the crypto user, covering main industry news, politics and regulation as well as consumer-level “news you can use” (practical stuff), including handy DIY tips, links to useful tools, unbiased reviews and opinions revolving around cryptocurrency. Simple logic and real-world examples are preferred before technical jargon and personal rants.

Categories

  • Altcoin
  • ApeCoin
  • Bitcoin
  • Blockchain
  • BNB
  • Cardano
  • Cryptocurrency
  • DOGE
  • DOT
  • Ethereum
  • HBAR
  • Litecoin
  • Market
  • Meta News
  • Mining
  • NFT
  • QNT
  • Regulation
  • SHIBA
  • Solano
  • Tether
  • Uncategorized
  • XDC
  • XLM
  • XRP

What’s New Here!

  • BNB Price Climbs Toward $733 as Volume and Whale Demand Increase – Brave New Coin
  • Rising Bets On Ethereum: Futures Open Interest Jumps To Fresh Multi-Month High
  • Pump.fun makes first acquisition, purchases Solana-based copy-trading wallet tracker Kolscan – The Block
  • ChatGPT's 42-Signal BNB Analysis Flags $670 Breakout Amid Corporate Treasury Revolution – Cryptonews
  • BNB Open Interest Crosses $780M After $1 Billion Token Burn: What Follows? – Coinspeaker

Subscribe Now

Our Partner

Round Main Logo
  • About Us
  • Privacy Policy
  • Contact Us

© 2022-2025 coin24h.com

No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining

© 2020 coin24h.com

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • bitcoinBitcoin (BTC) $ 116,559.00
  • ethereumEthereum (ETH) $ 2,955.91
  • tetherTether (USDT) $ 1.00
  • xrpXRP (XRP) $ 2.56
  • bnbBNB (BNB) $ 687.98
  • solanaSolana (SOL) $ 164.25
  • usd-coinUSDC (USDC) $ 0.999901
  • dogecoinDogecoin (DOGE) $ 0.197779
  • tronTRON (TRX) $ 0.294522
  • staked-etherLido Staked Ether (STETH) $ 2,955.18
  • cardanoCardano (ADA) $ 0.684050
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 116,493.00
  • hyperliquidHyperliquid (HYPE) $ 44.52
  • wrapped-stethWrapped stETH (WSTETH) $ 3,570.71
  • suiSui (SUI) $ 3.48
  • chainlinkChainlink (LINK) $ 15.33
  • bitcoin-cashBitcoin Cash (BCH) $ 519.16
  • stellarStellar (XLM) $ 0.302972
  • avalanche-2Avalanche (AVAX) $ 20.83
  • leo-tokenLEO Token (LEO) $ 9.02
  • hedera-hashgraphHedera (HBAR) $ 0.195086
  • wrapped-eethWrapped eETH (WEETH) $ 3,167.54
  • shiba-inuShiba Inu (SHIB) $ 0.000013
  • wethWETH (WETH) $ 2,955.79
  • usdsUSDS (USDS) $ 0.999891
  • the-open-networkToncoin (TON) $ 2.97
  • litecoinLitecoin (LTC) $ 95.17
  • whitebitWhiteBIT Coin (WBT) $ 46.73
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • moneroMonero (XMR) $ 327.19
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 116,592.00
  • polkadotPolkadot (DOT) $ 3.92
  • bitget-tokenBitget Token (BGB) $ 4.58
  • pepePepe (PEPE) $ 0.000013
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • uniswapUniswap (UNI) $ 8.37
  • aaveAave (AAVE) $ 304.99
  • pi-networkPi Network (PI) $ 0.513678
  • daiDai (DAI) $ 0.999985
  • bittensorBittensor (TAO) $ 378.47
  • aptosAptos (APT) $ 4.91
  • nearNEAR Protocol (NEAR) $ 2.54
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.18
  • crypto-com-chainCronos (CRO) $ 0.097684
  • okbOKB (OKB) $ 49.32
  • internet-computerInternet Computer (ICP) $ 5.46
  • jito-staked-solJito Staked SOL (JITOSOL) $ 199.56
  • ondo-financeOndo (ONDO) $ 0.900500
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • ethereum-classicEthereum Classic (ETC) $ 18.47