Capoae Malware
Summary
A new malware strain is being used in active attack campaigns to deliver crypto-mining payloads onto compromised systems. As initial vectors of compromise, the threat actors employ brute-force attacks again systems with weak credentials, while also exploiting several known vulnerabilities. The final payload delivered to the breached systems is an XMRig variant that will hijack the victims resources to mine for Monero coins, one of the more popular cryptocurrencies. First, Capoae will pick a seemingly legitimate system path from a list of potential locations. The final step is to either inject a new or update an existing Crontab entry that will execute the newly generated file.
Classifications
industries
Entertainment
applications
Customer Service & Support
AskAI Classifications
Labels
Cybersecurity Software
Anti-Malware Software
SaaS Security
Linked Companies
EnigmaSoft
$1M to $5M