When Microsoft revealed last May that millions of Windows devices had a serious hackable flaw known as BlueKeepone that could enable an automated worm to spread malware from computer to computerit seemed only a matter of time before someone unleashed a global attack. As predicted, a BlueKeep campaign has finally struck. But so far it's fallen short of the worst case scenario.
Security researchers have spotted evidence that their so-called honeypotsbait machines designed to help detect and analyze malware outbreaksare being compromised en masse using the BlueKeep vulnerability. The bug in Microsoft's Remote Desktop Protocol allows a hacker to gain full remote code execution on unpatched machines; while it had previously only been exploited in proofs of concept, it has potentially devastating consequences. Another worm that targeted Windows machines in 2017, the NotPetya ransomware attack, caused more than 10 billion dollars in damage worldwide.
But so far, the widespread BlueKeep hacking merely installs a cryptocurrency miner, leeching a victim's processing power to generate cryptocurrency. And rather than a worm that jumps unassisted from one computer to the next, these attackers appear to have scanned the internet for vulnerable machines to exploit. That makes this current wave unlikely to result in an epidemic.
"BlueKeep has been out there for a while now. But this is the first instance where Ive seen it being used on a mass scale," says Marcus Hutchins, a malware researcher for security firm Kryptos Logic who was one of the first to build a working proof-of-concept for the BlueKeep vulnerability. "Theyre not seeking targets. Theyre scanning the internet and spraying exploits."
"It hasnt hit critical mass yet."
Jake Williams, Rendition Infosec
Hutchins says that he first learned of the BlueKeep hacking outbreak from fellow security researcher Kevin Beaumont, who observed his honeypot machines crashing over the last few days. Since those devices exposed only port 3389 to the internetthe port used by RDPhe quickly suspected BlueKeep. Beaumont then shared a "crashdump," forensic data from those crashed machines, with Hutchins, who confirmed that BlueKeep was the cause, and that the hackers had intended to install a cryptocurrency miner on the victim machines, as detailed in this blog post from Kryptos Logic. Hutchins says he hasnt yet determined which coin theyre trying to mine, and notes that the fact the target machines crash indicate that the exploit may be unreliable. The malware's authors appear to be using a version of the BlueKeep hacking technique included in the open-source hacking and penetration testing framework Metasploit, Hutchins says, which was made public in September.
It's unclear also how many devices have been impacted, although the current BlueKeep outbreak appears to be far from the RDP pandemic that many feared. "I've seen a spike, but not the level I'd expect from a worm," says Jake Williams, a founder of the security firm Rendition Infosec, who has been monitoring his clients' networks for signs of exploitation. "It hasnt hit critical mass yet."
In fact, Williams argues, the absence of a more severe wave of BlueKeep hacking so far may actually indicate a success story for Microsoft's response to its BlueKeep bugan unexpected happy ending. "Every month that passes by without a worm happening, more people patch and the vulnerable population goes down," Williams says. "Since the Metasploit module has been out for a couple of months now, the fact that no one has wormed this yet seems to indicate theres been a cost-benefit analysis and theres not a huge benefit to weaponizing it."
But the threat BlueKeep poses to hundreds of thousands of Windows machines hasn't passed just yet. About 735,000 Windows computers remained vulnerable to BlueKeep according to one internet-wide scan by Rob Graham, a security researcher and founder of Errata Security, who shared those numbers with WIRED in August. And those machines could still be hit with a more seriousand more virulentspecimen of malware that exploits Microsoft's lingering RDP vulnerability. That could take the form of a ransomware worm in the model of NotPetya or also WannaCry, which infected almost a quarter million computers when it spread in May of 2017, causing somewhere between $4 and $8 billion damage.
See the original post here:
The First BlueKeep Mass Hacking Is Finally Herebut Don't Panic - WIRED
- New Bitcoin-Esque Cryptocurrency Named After Kanye West Launching [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- Coinye West: A new cryptocurrency for the masses and an ode to Kanye [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- Cryptocurrency gets hip: 'Coinye West' [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- As Bitcoin Soars in Value, Alternative Cryptocurrencies, Such ... [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- AltCoins - Crypto()Currency - Cryptocurrency [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- CryptoCurrency.org [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- DimeCoin - The New Cryptocurrency - Video [Last Updated On: January 5th, 2014] [Originally Added On: January 5th, 2014]
- Kanye West Sues Amazon, Others Over 'Coinye West' Cryptocurrency [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- $25,000 in Dogecoin raised to save the Jamaican bobsled team [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Gotangco: Is PH ready for Bitcoin and cryptocurrency? [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- As Bitcoin Soars in Value, Alternative Cryptocurrencies ... [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Cryptominer.de Avalon 200GH/S Bitcoin Miner Asic 55nm Mining Cryptocurrency - Video [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Cryptocurrency mining Rig build 1 - Video [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Bitcoin Value and rise of the cryptocurrency - Video [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- LeadCoin - Cryptocurrency - Video [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Cryptocurrency Mining [Part 2] - Video [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Cryptocurrency Mining [Part 1] - Video [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Know How 74: Cryptocurrency - Video [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- Worlds First BITCOIN ATM Opens in Vancouver Canada - Is CryptoCurrency the Future Currency? - Video [Last Updated On: January 22nd, 2014] [Originally Added On: January 22nd, 2014]
- 42 Coin cryptocurrency contest - Video [Last Updated On: January 23rd, 2014] [Originally Added On: January 23rd, 2014]
- What is Bitcoin anyway? [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- The rise and rise of dogecoin, the internet's hottest cryptocurrency [Last Updated On: January 24th, 2014] [Originally Added On: January 24th, 2014]
- Cryptocurrency Mining Rigs by plugNmine - Video [Last Updated On: January 26th, 2014] [Originally Added On: January 26th, 2014]
- How Cryptocurrency, Crowdfunding And A Little Internet Altruism Saved Jamaica’s Hopes For Bobsled Gold [Last Updated On: January 27th, 2014] [Originally Added On: January 27th, 2014]
- Introducing Dogecoin the Greatest Cryptocurrency - Video [Last Updated On: January 27th, 2014] [Originally Added On: January 27th, 2014]
- Dogecoin - Wikipedia, the free encyclopedia [Last Updated On: January 28th, 2014] [Originally Added On: January 28th, 2014]
- Dummy plug for GPU for cryptocurrency mining - Video [Last Updated On: January 28th, 2014] [Originally Added On: January 28th, 2014]
- My first CryptoCurrency Miner up and running yet partially completed - Video [Last Updated On: January 28th, 2014] [Originally Added On: January 28th, 2014]
- Thought of the Day - 01 / 28 / 2014 - CryptoCurrency - Dogecoin - What is this? - Video [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- Wall Street's Cryptocurrency Headquarters: Inside Bitcoin Center NYC - Video [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- My Take on the Profitablity of Cryptocurrency - Video [Last Updated On: January 30th, 2014] [Originally Added On: January 30th, 2014]
- Bitcoin steps a little closer to acceptance [Last Updated On: January 31st, 2014] [Originally Added On: January 31st, 2014]
- Bitcoin gets two hearings - and steps closer to acceptance [Last Updated On: January 31st, 2014] [Originally Added On: January 31st, 2014]
- Dogecoin cryptocurrency donors help send Indian athletes to Sochi [Last Updated On: January 31st, 2014] [Originally Added On: January 31st, 2014]
- How To Create Your Own Cryptocurrency [Last Updated On: January 31st, 2014] [Originally Added On: January 31st, 2014]
- Cryptocurrency - Bitcoin Song (by 13inlet) - Video [Last Updated On: January 31st, 2014] [Originally Added On: January 31st, 2014]
- Selling Dem Coins - How to convert your Cryptocurrency - Tutorial - Video [Last Updated On: February 1st, 2014] [Originally Added On: February 1st, 2014]
- Dogecoin - From joke cryptocurrency to Bitcoin rival - Video [Last Updated On: February 1st, 2014] [Originally Added On: February 1st, 2014]
- New York to Regulate Bitcoin: Is the Cryptocurrency Biz Like "the Wild West?" - Video [Last Updated On: February 1st, 2014] [Originally Added On: February 1st, 2014]
- Dogecoin: A 2014 Cryptocurrency Revolution - Video [Last Updated On: February 1st, 2014] [Originally Added On: February 1st, 2014]
- U.S. Treasury Goes Easy on the Bitcoin [Last Updated On: February 3rd, 2014] [Originally Added On: February 3rd, 2014]
- WoW - Dogecoin The #1 Cryptocurrency - Video [Last Updated On: February 3rd, 2014] [Originally Added On: February 3rd, 2014]
- The Dark Horse of Cryptocurrency - Franko - Video [Last Updated On: February 3rd, 2014] [Originally Added On: February 3rd, 2014]
- Think Bitcoin is Expensive? Try 42 Coin, The £100,000 Cryptocurrency [Last Updated On: February 4th, 2014] [Originally Added On: February 4th, 2014]
- We Love DogeCoin The #1 Cryptocurrency - Video [Last Updated On: February 4th, 2014] [Originally Added On: February 4th, 2014]
- Cryptocurrency Hackathon will talk Bitcoin, Dogecoin and more for coders and novices [Last Updated On: February 5th, 2014] [Originally Added On: February 5th, 2014]
- Dogecoin Kiss: An original song about the world's friendliest Cryptocurrency - Video [Last Updated On: February 5th, 2014] [Originally Added On: February 5th, 2014]
- Cryptocurrency Hackathon will talk Bitcoin, Dogecoin and ... [Last Updated On: February 6th, 2014] [Originally Added On: February 6th, 2014]
- Dogecoin: cryptocurrency passes Bitcoin to reach the moon - Video [Last Updated On: February 6th, 2014] [Originally Added On: February 6th, 2014]
- ZedCoin new CryptoCurrency - Video [Last Updated On: February 7th, 2014] [Originally Added On: February 7th, 2014]
- LiteCoin Trading Robot LTC Robot Cryptocurrency Trading Robot - Video [Last Updated On: February 7th, 2014] [Originally Added On: February 7th, 2014]
- Apple approves Dogecoin app after removing Bitcoin app [Last Updated On: February 8th, 2014] [Originally Added On: February 8th, 2014]
- Cryptocurrency - Wikipedia, the free encyclopedia [Last Updated On: February 9th, 2014] [Originally Added On: February 9th, 2014]
- Cryptocurrency, Permaculture, and 3D Printing - Video [Last Updated On: February 9th, 2014] [Originally Added On: February 9th, 2014]
- Litecoin Robot | The World's First Litecoin Trading Bot Review | Scrypt Money | Cryptocurrency LTC - Video [Last Updated On: February 9th, 2014] [Originally Added On: February 9th, 2014]
- Bitcoin Slump Shows the $8 Billion Cryptocurrency Lacks Mature Infrastructure [Last Updated On: February 10th, 2014] [Originally Added On: February 10th, 2014]
- WE WIN COINS - EXCLUSIVE CRYPTOCURRENCY BETTING SOFTWARE TO INCREASE WINS - Video [Last Updated On: February 10th, 2014] [Originally Added On: February 10th, 2014]
- Dogecoin Value Soars $40M in Value Following Chinese Exchange Opens [Last Updated On: February 12th, 2014] [Originally Added On: February 12th, 2014]
- Cryptocurrency News Round-Up: Protests at Mt Gox as ... [Last Updated On: February 12th, 2014] [Originally Added On: February 12th, 2014]
- Dogecoin Soars $40M in Value Following Chinese Exchange Opens [Last Updated On: February 14th, 2014] [Originally Added On: February 14th, 2014]
- Is the new cryptocurrency PotCoin worth it? A Crypto-Market-News review of PotCoin - Video [Last Updated On: February 14th, 2014] [Originally Added On: February 14th, 2014]
- Cryptocurrency Expert - Lorraine Murphy - Video [Last Updated On: February 14th, 2014] [Originally Added On: February 14th, 2014]
- CryptoCurrency Con 2013 - Cathy Reisenwitz - Why a Free Society Needs a Free Money - Video [Last Updated On: February 14th, 2014] [Originally Added On: February 14th, 2014]
- How to transfer Bitcoins from one cryptocurrency exchange to another cryptocurrency exchange - Video [Last Updated On: February 14th, 2014] [Originally Added On: February 14th, 2014]
- Cryptocurrency Explained The Tech Guy 1046127 - Video [Last Updated On: February 14th, 2014] [Originally Added On: February 14th, 2014]
- CryptoCurrency Hacking Hard - Video [Last Updated On: February 14th, 2014] [Originally Added On: February 14th, 2014]
- ** UPDATE ** Computer, Cryptocurrency, Games and More!! - Video [Last Updated On: February 15th, 2014] [Originally Added On: February 15th, 2014]
- The glitch that will help kill Bitcoin [Last Updated On: February 16th, 2014] [Originally Added On: February 16th, 2014]
- Skinny Puppy at GITMO, NSA Myths, Dogecoin and Cryptocurrency #TMS 2/15/2014 - Video [Last Updated On: February 16th, 2014] [Originally Added On: February 16th, 2014]
- PotCoin, the cryptocurrency for the Cannabis Industrie - Video [Last Updated On: February 16th, 2014] [Originally Added On: February 16th, 2014]
- cryptocurrency mining rig - Video [Last Updated On: February 17th, 2014] [Originally Added On: February 17th, 2014]
- Quark - The Best Cryptocurrency - Video [Last Updated On: February 17th, 2014] [Originally Added On: February 17th, 2014]
- Cryptocurrencies: I Lived on Bitcoin for a Week - Video [Last Updated On: February 17th, 2014] [Originally Added On: February 17th, 2014]
- Cryptocurrencies: The State of Play - Video [Last Updated On: February 17th, 2014] [Originally Added On: February 17th, 2014]
- AMD graphics card pricing skyrockets due to cryptocurrency mining, could kill AMD’s gaming efforts [Last Updated On: February 18th, 2014] [Originally Added On: February 18th, 2014]
- Could there be a $50,000 bitcoin? [Last Updated On: February 18th, 2014] [Originally Added On: February 18th, 2014]
- CRYPTOCURRENCY - Bitcoin Overview... - Video [Last Updated On: February 18th, 2014] [Originally Added On: February 18th, 2014]
- CRYPTOCURRENCY - Money Changer Den of Thieves, The Federal Reserve - Video [Last Updated On: February 18th, 2014] [Originally Added On: February 18th, 2014]
- How to Buy PotCoins Part 2: Make a cryptocurrency trading account at swissex.com to buy PotCoin - Video [Last Updated On: February 18th, 2014] [Originally Added On: February 18th, 2014]
- BitPagar cryptocurrency - Video [Last Updated On: February 18th, 2014] [Originally Added On: February 18th, 2014]