Smominru Malware Affecting 4,700 Computers Every Day, Researchers Claim

China, Taiwan, Russia, Brazil, and the US have seen the most attacks.

Advertisement
By Indo-Asian News Service | Updated: 8 October 2019 10:59 IST

Security researchers have discovered that the Smominru malware infected 90,000 machines worldwide during the month of August, with an infection rate of up to 4,700 computers per day. In its post-infection phase, it steals victim credentials, installs a Trojan module and a cryptominer and propagates inside the network, according to researchers from Guardicore, a data centre and cloud security company.

The botnet uses several methods to propagate, but primarily it infects a system in one of two ways -- either by brute-forcing weak credentials for different Windows services, or more commonly by relying on the infamous EternalBlue exploit, cyber-security firm Kaspersky said in a blog post last week.

Even though Microsoft patched the vulnerability EternalBlue exploits, which made the WannaCry and NotPetya outbreaks possible, many companies are simply ignoring updates, Kaspersky said.

Advertisement

China, Taiwan, Russia, Brazil, and the US have seen the most attacks, but that doesn't mean other countries are out of its scope. For example, the largest network Smominru targeted was in Italy, with 65 hosts infected.

Advertisement

The criminals involved are not too particular about their targets, which range from universities to healthcare providers.

However, one detail is very consistent. About 85 percent of infections occur on Windows 7 and Windows Server 2008 systems. The rest include Windows Server 2012, Windows XP and Windows Server 2003.

Advertisement

After compromising the system, Smominru creates a new user, called admin$, with admin privileges on the system and starts to download a whole bunch of malicious payloads.

The most obvious objective is to silently use infected computers for mining cryptocurrency (namely, Monero) at the victim's expense.

Advertisement

The malware also downloads a set of modules used for spying, data exfiltration, and credential theft.

On top of that, once Smominru gains a foothold, it tries to propagate further within the network to infect as many systems as possible.

To protect their network, computers, and data from Smominru, users need to update operating systems and other software regularly, Kaspersky said.

It is also important for users to use strong passwords. A reliable password manager that helps you create, manage, and automatically retrieve and enter passwords may help protect you against brute-force attacks.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Smominru, Kaspersky
Advertisement
Popular Mobile Brands
  1. These Samsung Phones Will Get Price Drops Ahead of Festive Season
  2. Biggest Offers on Smartphones During Amazon Great Indian Festival Sale
  3. OTT Releases This Week: Mahavatar Narsimha, The Bads of Bollywood, and More
  4. Samsung Galaxy A17 4G Goes Official With MediaTek Helio G99 SoC
  5. Vivo, iQOO Smartphones Likely to Switch to Origin OS in India
  6. Amazon Sale 2025: Top Deals on Logitech, Dell, HP, and More PC Accessories
  7. Flipkart Big Billion Days Sale: iPhone 17 Available With 10-Minute Delivery
  8. iQOO 15 is All Set to Launch in China Next Month
  9. Instamart Quick India Movement Sale 2025: Best Offers on Electronics
  1. Vivo, iQOO Smartphones Likely to Switch to Origin OS in India, Replacing Funtouch OS
  2. iPhone 18 Pro Models Tipped to Retain iPhone 17 Pro Design, Could Feature Transparent Back
  3. Tencent Says Sony 'Monopolising' Genre Conventions, Seeks Dismissal of Light of Motiram Lawsuit
  4. Samsung Galaxy A17 4G Launched With MediaTek Helio G99 SoC, 5,000mAh Battery: Price, Specifications
  5. Instamart Quick India Movement Sale 2025 Goes Live: Best Offers on Smartphones, Smartwatches and More
  6. Bitcoin Stabilises Near $116,900 as Altcoins Push Higher
  7. Mahavatar Narsimha Now Streaming on Netflix: Everything You Need to Know About This Animated Mythological Drama
  8. Nintendo Switch Online Adds First Third-Party Game Boy Advance Titles from Namco This September
  9. Big Billion Days Sale: Flipkart Minutes Promises Doorstep Delivery of iPhone 17, Galaxy S24 in 10 Minutes
  10. Amazon Sale 2025: Top Deals on Logitech, Dell, HP, and More PC Accessories
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.