Autom Malware
Summary
Experts report that the attackers behind the Autom campaign are evolving their methods, making malware threats more capable of evading defense mechanisms and flying under the radar of anti-virus scanning tools. Initial attacks of this campaign involved executing a threatening command, once a user runs a vanilla image with the name "alpine:latest." While the threatening command added to the corrupted vanilla image has barely been changed over time, malware researchers have identified a difference in the server from which the shell script is being downloaded. Along with the already known vulnerabilities that cybercriminals usually exploit for conducting crypto-mining attacks, in recent weeks, security flaws in the Log4j logging library have been abused to execute a scheme called crypto-jacking, which also involves hijacking machines with the purpose of mining crypto-currencies. At the same time, the network-attached storage (NAS) appliance maker QNAP also has announced recently the discovery of a cryptocurrency mining malware that could occupy around 50% of the total CPU usage.