Cryptominer LoudMiner disguises as VST-plug-ins and programs for recording music

in #music5 years ago (edited)

Pirate music software is a common phenomenon in the music industry, which continues to live and develop. Every year, numerous release groups distribute gigabytes of hardware software, but until today, the credibility of ISO and RAR archives was high.

The latest report from the developers of the ESET Antivirus antivirus says that pirates used the musicians computers unnoticed to extract Bitcoin and other cryptocurrencies through the hidden miner LoudMiner. ESET researchers published an article called “LoudMiner: Cross-platform mining in cracked VST software,” which reported that they analyzed 137 images and archives with plug-ins and other music programs.

DVByDsZW0AYzt5t.jpg

This list includes free versions of such popular programs and plug-ins as Native Instruments Kontakt 5.7, Propellerhead Reason, Ableton Live, Lennar Digital Sylenth1, ReFX Nexus and Antares AutoTune, downloaded from major torrent trackers and Varez blogs. Most of the archives and installers were supplied with the crypto miner LoudMiner, which was installed in the system along with the main software for working with sound.

According to the report, creators of LoudMiner cryptominer used the fact that VST-plug-ins and DAW heavily load the computer's processor - it was maxed out by working samplers, synthesizers and equalizers. Users did not notice the work of the miner, writing off the increased load on the system to work plug-ins, although in fact the computer was used for the extraction of cryptocurrency.

Djag6giXsAAv4dO.jpg

The first messages about LoudMiner appeared in August 2018, and Native Instruments Kontakt is considered to be the first infected program. Gradually, the network reported on increased processor activity when working with music programs and plug-ins, with the peak of user complaints in June 2019.

According to the researchers, the crypto miner works using QEMU virtualization programs on macOS and VirtualBox on Windows. During installation, the miner penetrates deeply into the system and after a while begins to produce Monero cryptocurrency. At the same time, the principle of LoudMiner operation is rather cunning: it is copied into macOS during installation by a special script and hangs in memory by the unkillable qemu-system-x86_64 process, in Windows it disguises the need to install the VirtualBox driver.

ESET recommends that all users check their system for viruses and avoid pirated software. You can read the study details and conclusions of ESET here.

Sort:  

Thank you nesmeliy! You've just received an upvote of 3% by artturtle!


Learn how I will upvote each and every one of your posts



Please come visit me to see my daily report detailing my current upvote power and how much I'm currently upvoting.

Oh wow thanks for the info

Posted using Partiko iOS

Hello @nesmeliy, thank you for sharing this creative work! We just stopped by to say that you've been upvoted by the @creativecrypto magazine. The Creative Crypto is all about art on the blockchain and learning from creatives like you. Looking forward to crossing paths again soon. Steem on!

Coin Marketplace

STEEM 0.20
TRX 0.15
JST 0.029
BTC 64344.88
ETH 2629.39
USDT 1.00
SBD 2.83