Linux Trojan Written In Go Mines For Cryptocurrencies

A Linux Trojan written entirely in Googles ‘Go’ programming language is infecting computers and installing programs that mine for cryptocurrencies.

The malware, known as ‘Linux.Lady.1’ consists entirely of libraries published on the GitHub repository and although researchers at Russian cybersecurity firm Doctor Web said they had encountered Go Trojans before, it was not common to find them in the wild.

Linux Torjan

Once it launches, the Trojan sends the Linux version running on the infected system, the OS family, CPU, names and processes to a command and control server.

It then receives a configuration file that downloads the cryptocurrency mining application and a special website that can be used to determine the external IP of the system.

This is used to infect other machines on the network and to generate income by mining the ‘Moreno’ currency, which is then sent to a digital wallet.

The exploit makes use of misconfigured REmote DIctionary Server (Redis) NoSQL servers which do not have passwords or other security mechanisms enabled by default. This allows the malware to spread.

This is because the open source project, previously backed by the likes of VMware and Pivotal, prioritises performance and so end users must enable such features for protection.

According to a Risk Based Security report, as many as 30,239 Redis servers are found on search engine Shodan and 6,338 installations are compromised, dating back to version 1.2. The current stable release is 3.2.1, meaning significant numbers are vulnerable for exploitation.

Quiz: What do you know about Linux?

Steve McCaskill

Steve McCaskill is editor of TechWeekEurope and ChannelBiz. He joined as a reporter in 2011 and covers all areas of IT, with a particular interest in telecommunications, mobile and networking, along with sports technology.

Recent Posts

FTX To Repay Creditors In Full, $11 Billion

Good news for creditors. CEO John Ray III says bankrupt crypto exchange FTX will be…

14 hours ago

US Revokes Some Intel, Qualcomm China Export Licences – Report

Chip giants Intel and Qualcomm complain of sales impact after United States revokes some of…

15 hours ago

EU Requests Content Moderation Data From X

Using the Digital Services Act, European Commission asks X (formerly Twitter) for details over reduction…

17 hours ago

Chinese Hack Exposes Ministry Of Defence Payroll Data

Payroll records of nearly all members of the UK's armed forces have been exposed, reportedly…

17 hours ago

Apple ‘Let Loose’ Event Updates iPad Air, iPad Pro, Accessories

Updates arrive for two iPad models (iPad Air and iPad Pro) as well as some…

20 hours ago

TikTok Sues To Halt US Divest Or Ban Law

US government sued by TikTok in bid to block law that will force sale of…

22 hours ago