{"id":375817,"date":"2020-02-21T07:33:07","date_gmt":"2020-02-21T05:33:07","guid":{"rendered":"https:\/\/businesstech.co.za\/news\/?p=375817"},"modified":"2020-02-21T08:09:31","modified_gmt":"2020-02-21T06:09:31","slug":"sophos-mykings-report-the-growth-of-a-relentless-botnet","status":"publish","type":"post","link":"https:\/\/businesstech.co.za\/news\/industry-news\/375817\/sophos-mykings-report-the-growth-of-a-relentless-botnet\/","title":{"rendered":"Sophos MyKings report &#8211; The growth of a relentless botnet"},"content":{"rendered":"<p><a href=\"https:\/\/www.sophos.com\/en-us\/labs.aspx?utm_source=BusinessTech&amp;utm_medium=Article&amp;utm_campaign=21Feb2020\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>SophosLabs<\/strong><\/a>\u2019 report <a href=\"https:\/\/www.sophos.com\/en-us\/medialibrary\/pdfs\/technical-papers\/sophoslabs-uncut-mykings-report.pdf?utm_source=BusinessTech&amp;utm_medium=Article&amp;utm_campaign=21Feb2020\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>MyKings: The Slow but Steady Growth of a Relentless Botnet<\/strong><\/a>, details the morphing attack components of the globally-reaching MyKings cryptominer.<\/p>\n<p>\u201cMyKings contains the perfect storm of attack methods highlighted in <a href=\"https:\/\/www.sophos.com\/en-us\/labs\/security-threat-report.aspx?utm_source=BusinessTech&amp;utm_medium=Article&amp;utm_campaign=21Feb2020\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>SophosLabs\u2019 2020 Threat Report<\/strong><\/a> \u2013 access through open remote services, botnets to orchestrate parts of the attack, and Living off the Land (LotL) to evade detection \u2013 that are used to drop cryptominers,\u201d said Ross Anderson, Sophos Product Development Manager at Duxbury Networking.<\/p>\n<ul>\n<li><a href=\"https:\/\/store.duxbury.co.za\/?utm_source=MyBroadband&amp;utm_medium=Article&amp;utm_campaign=21Feb2020\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>Click here to find out more from Duxbury Networking.<\/strong><\/a><\/li>\n<\/ul>\n<p>\u201cThe report covers the interaction between all of these components and their chain reaction to impact computers. The report also analyses cybercriminal behaviours to further explain the characteristics of MyKings.\u201d<\/p>\n<p>\u201cHigh-end or nation-state sponsored cyberattackers have the resources to purchase or develop zero-day exploits themselves. On the flip side, low-end cybercriminals use cheap or free builder kits available in underground, dark web forums, but lack the skills to do anything except execute the builders,\u201d said Anderson.<\/p>\n<p>\u201cThe MyKings group is in between these two categories; they are the \u2018SMB of cybercrime\u2019. These criminals don\u2019t invest money into expensive tools, but they have the skills and development power to modify and enhance open source components.\u201d<\/p>\n<p>\u201cTheir modus operandi is to invest significant amounts of development time into customising the public domain tools they are using. This is a reminder that cybercriminals are enhancing their capabilities all the time and defenders should adopt this mindset for best security practices,\u201d Anderson pointed out.<\/p>\n<p>MyKings has evolved over time, with cybercriminals adding support for the EternalBlue exploit into newer versions of MyKings.<\/p>\n<p>This functionality is not integrated into the spreader program, but rather exists as a separate executable, converted from Python scripts, that is downloaded and executed by the main spreader program.<\/p>\n<div id=\"attachment_375829\" style=\"width: 650px\" class=\"wp-caption aligncenter\"><a  data-lightbox=\"post-image\" href=\"https:\/\/businesstech.co.za\/news\/wp-content\/uploads\/2020\/02\/SophosLabs-Map.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-375829\" class=\"wp-image-375829\" src=\"https:\/\/businesstech.co.za\/news\/wp-content\/uploads\/2020\/02\/SophosLabs-Map.png\" alt=\"\" width=\"640\" height=\"317\" srcset=\"https:\/\/businesstech.co.za\/news\/wp-content\/uploads\/2020\/02\/SophosLabs-Map.png 940w, https:\/\/businesstech.co.za\/news\/wp-content\/uploads\/2020\/02\/SophosLabs-Map-300x148.png 300w, https:\/\/businesstech.co.za\/news\/wp-content\/uploads\/2020\/02\/SophosLabs-Map-768x380.png 768w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/a><p id=\"caption-attachment-375829\" class=\"wp-caption-text\">Figure 1<\/p><\/div>\n<p>As indicated in the <a href=\"https:\/\/news.sophos.com\/en-us\/2019\/12\/18\/mykings-botnet-spreads-headaches-cryptominers-and-forshare-malware?utm_source=BusinessTech&amp;utm_medium=Article&amp;utm_campaign=21Feb2020\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>MyKings report<\/strong><\/a>, the worldwide activity map (see Figure 1) includes approximately 45,000 impacted hosts.<\/p>\n<p>Top countries include China, Taiwan, Russia, Brazil, United States, India, and Japan.<\/p>\n<p>Other key findings of the report include:<\/p>\n<ul>\n<li>The botnet can spread by attacking weak username\/password combinations via MySQL, MSSQL, telnet, ssh, IPC, WMI, RDP, CCTV connections.<\/li>\n<li>The main payloads are the Forshare trojan and various Monero cryptominers. The botnet still mines about 5 XMR (R4,480), per day.<\/li>\n<\/ul>\n<p>Anderson offers the following advice:<\/p>\n<ul>\n<li>Keep computers up-to-date with security patches. MyKings uses EternalBlue, which was patched two years ago.<\/li>\n<li>Change default passwords and apply strong, unique passwords. MyKings uses known weak passwords to attack web services.<\/li>\n<li>Don\u2019t expose Server Message Block (SMB), Remote Desktop Protocol (RDP) and similar remote access services to the Internet.<\/li>\n<li>Use up-to-date security software. <a href=\"https:\/\/www.sophos.com\/en-us\/products\/intercept-x.aspx?utm_source=BusinessTech&amp;utm_medium=Article&amp;utm_campaign=21Feb2020\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>Sophos Intercept X<\/strong><\/a> provides protection at several points.<\/li>\n<\/ul>\n<p>\u201cWe urge users to contact our team to discuss the benefits of deploying Sophos Intercept X in their organisations,\u201d said Anderson.<\/p>\n<p>For more information contact Duxbury Networking, +27 (0) 11 351 9800, <a href=\"mailto:info@duxnet.co.za\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>info@duxnet.co.za<\/strong><\/a>, <a href=\"https:\/\/store.duxbury.co.za\/?utm_source=MyBroadband&amp;utm_medium=Article&amp;utm_campaign=21Feb2020\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>store.duxbury.co.za<\/strong><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>SophosLabs\u2019 report MyKings: The Slow but Steady Growth of a Relentless Botnet, details the morphing attack components of the globally-reaching MyKings cryptominer.<\/p>\n","protected":false},"author":57,"featured_media":375819,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10459],"tags":[14323,26],"class_list":["post-375817","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-industry-news","tag-duxbury-networking","tag-headline"],"_links":{"self":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/375817","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/users\/57"}],"replies":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/comments?post=375817"}],"version-history":[{"count":9,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/375817\/revisions"}],"predecessor-version":[{"id":375865,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/375817\/revisions\/375865"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/media\/375819"}],"wp:attachment":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/media?parent=375817"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/categories?post=375817"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/tags?post=375817"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}