Denonia Malware

General News

Summary

A piece of intrusive malware named Denonia is being used in threatening operations targeting Amazon Web Services (AWS) Lambda installations. XMRig is a popular crypto-miner often used by cybercriminals to hijack the hardware resources of the breached device to mine for the Monero cryptocurrency. After analyzing the threat, researchers discovered that despite having the file name python, Denonia was created using the Go programming language. The researchers speculate that Denonias curious use of DNS over HTTPS (DOH) achieved via the doh-go library was implemented as a countermeasure to stop AWS from detecting the threats lookups due to its unsafe domains. At the moment, no conclusive evidence pointing to the exact infection vector used in the attacks involving Denonia malware has been found.

Classifications

industries
Entertainment
applications
Customer Service & Support

AskAI Classifications

Labels
Cybersecurity Software Anti-Malware Software SaaS Security

Linked Companies

EnigmaSoft
$1M to $5M