Crypto Mining Malware Hidden in Pictures
Beauty and the Beast! Cryptocurrency mining malware is being hidden in click-bait pictures. This is another way to attackers to potentially compromise victims that ultimately download the mining program which will direct financial benefits to the attacker. Behavioral hacks aren't going away anytime soon.
Security researchers at Imperva have identified a campaign in which attackers append malicious binary code into a picture which leverages SQL to be extraced and executed. The code was found embedded in a picture of Scarlett Johansson on a public image site, and initiated cryptocurrency Monero mining malware.
Imperva's full technical breakdown can be read here: https://www.imperva.com/blog/2018/03/deep-dive-database-attacks-scarlett-johanssons-picture-used-for-crypto-mining-on-postgre-database/
Expect crypto-mining malware to use every known method in the attackers playbook to find victims: spam, phishing, infected websites, malicious ads, office attachments, worms, fake patches, trojan apps, etc.
Everything.
Does it mine if my Javascript it disabled unless I whitelist it?
I whitelisted steemit, is it enough to be hacked like this?
Or does it only hack morons whom have all Javascript enabled, i.e., using Firefox?
Untypically for me, I upvoted despite feeling too late to do it, more typically, while still not typically, I resteemed and more typically I followed.
This comment has received a 72.99 % upvote from @steemdiffuser thanks to: @stimialiti. Steem on my friend!
Above average bids may get additional upvotes from our trail members!
Get Upvotes, Join Our Trail, or Delegate Some SP
Its so sad this happens. We have very little governments support for cryptos and such things lower crypto support from crypto fans themselves.
good, to progress
Great update buddy @mrosenquist...
Crypto mining malware hidden in pictures !!!!!!!!!!
Your article is very helpful for security ....Thanks for sharing with us an effective update
this function of security.
crypton mining malware hidden in pitcure.
Im currently using No coin plugin on my chrome browser would it help stop explouts like this running my machine?
Thanks for share this @mrosenquist
Keep doing good work
i just upvote as i like it pls support me as i am new on steemit by upvoting me