Capoae Malware

General News

Summary

A new malware strain is being used in active attack campaigns to deliver crypto-mining payloads onto compromised systems. As initial vectors of compromise, the threat actors employ brute-force attacks again systems with weak credentials, while also exploiting several known vulnerabilities. The final payload delivered to the breached systems is an XMRig variant that will hijack the victims resources to mine for Monero coins, one of the more popular cryptocurrencies. First, Capoae will pick a seemingly legitimate system path from a list of potential locations. The final step is to either inject a new or update an existing Crontab entry that will execute the newly generated file.

Classifications

industries
Entertainment
applications
Customer Service & Support

AskAI Classifications

Labels
Cybersecurity Software Anti-Malware Software SaaS Security

Linked Companies

EnigmaSoft
$1M to $5M