Skip to content
Menu
Bayou Technologies | Lake Charles, Louisiana | Technology | Cybersecurity | Communication | Marketing
Computer IT Services & Marketing
  • Technology
    • Managed Services
    • Computer Repair
    • Consulting
  • Cybersecurity
    • BDR
    • Network Security
    • Computer Security
    • Data Recovery
  • Communication
    • Cabling
    • Wireless Networking
    • Phones
  • Marketing
    • Website Development
    • Search Engine Optimization
    • Social Media & Online Presence
    • Location Scan
    • Website & Email Management
    • Online Advertising
    • Multimedia Design
    • Newsletter
  • CALL: 337-214-1172
Widgets

HOME  |  BLOG  |  REMOTE SUPPORT

Home
Support
Blog
Contact
Close Menu
New Powerful Malware Is Targeting Windows-Based Machines
July 7 2020

New Powerful Malware Is Targeting Windows-Based Machines

wukovits Blog, General Interest, Malware and Virus Protection, Recent News, Security, Technology News

Researchers have discovered a devilishly clever new stain of malware currently in use by hackers around the world. The new strain is appropriately called “Lucifer,” and has been making life quite difficult for IT professionals managing Windows environments.

The malware exploits critical vulnerabilities in Windows-based systems to launch DDoS attacks and install cryptojacking code.

The latest version (2.0) of the code was discovered by researchers Durgesh Sangvikar, Zhibin Zhang, Chris Navarrete, and Ken Hsu, on May 29, 2020. They discovered it while investigating the exploit of CVE-2019-9081, which is a deserialization bug in Laravel Framework that can be used to conduct RCE (Remote Code Execution) attacks.

Their research revealed that CVE-2019-9081 is just one of many critical security flaws Lucifer exploits, including:

  • CVE-2014-6287
  • CVE-2018-1000861
  • CVE-2017-10271
  • CVE-2018-20062
  • CVE-2018-7600
  • CVE-2017-9791
  • CVE-2019-9081
  • CVE-2017-0144
  • CVE-2017-0145
  • CVE-2017-8464

Few malware strains incorporate code designed to exploit so many different security flaws, which makes Lucifer a serious threat indeed.

If there’s a silver lining to be found, it is in the fact that all of these flaws have already been addressed via patches. So it comes down to making sure your software is up to date and running the latest and greatest security patches. The researchers who discovered it say that there are ongoing campaigns that are currently wreaking havoc on un-patched systems and urge all system admins to make sure the software they’re running is patched as soon as possible.

In practice, Lucifer 2.0 works by scanning for open TCP ports 135 (RPC) and 1433 (MSSQL). When it finds a potential target, it will use credential-stuffing attacks to gain access to the targeted system. Once it gains a foothold, it installs XMRig, which is a program used to covertly mine Monero (XMR) cryptocurrency. Additionally, the malware connects to a command and control server where it can receive additional instructions.

As we said, it’s a serious piece of work and not to be taken lightly.

Used with permission from Article Aggregator

Microsoft Changing Their Physical Retail Stores And Flagship Locations Nvidia GPU Users Should Update As New Security Patches Released

Related Posts

Some MacBook Pros May Have Battery Charging Issue

Apple, Blog, General Interest, Recent News, Technology News

Some MacBook Pros May Have Battery Charging Issue

Update To Popular Android App Included Malware Infection

Android, Blog, Google, Malware and Virus Protection, Security, Technology News

Update To Popular Android App Included Malware Infection

Data Breach Victims Get More Spam And Phishing Emails

Blog, Data Breach, General Interest, Gmail, Recent News, Security, Technology News

Data Breach Victims Get More Spam And Phishing Emails

Recent Posts

  • Some MacBook Pros May Have Battery Charging Issue
  • Update To Popular Android App Included Malware Infection
  • Data Breach Victims Get More Spam And Phishing Emails

Archives

Categories

Get a Domain Registered


$.99* .COM Domain! Get going with GoDaddy!

Back To Top
Bayou Technologies | Lake Charles, Louisiana | Technology | Cybersecurity | Communication | Marketing
  • Home
  • Technology
  • Cybersecurity
  • Communication
  • Marketing
  • Newsletter
  • Blog
  • Support
  • Contact

BBB Logo

Bayou Technologies, LLC
✖
Bayou Technologies is a BBB Accredited Busines
A+
On a scale of A+ to F

Reviewed, Evaluated and Accredited

Meets All 26 Standards of Accreditation

BBB Accredited since 1/1/2012

Click here for BBB Business Report on Bayou Technologies, LLC

BBB Accredited:

BBB Rating as of:

Verify Bayou Technologies, LLC
Bayou Technologies, LLC © 2019
Website Development and Marketing in Lake Charles, Louisiana
This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are as essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled

Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.

Non-necessary

Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.

SAVE & ACCEPT