Clipminer Botnet Makes Operators at Least $1.7 Million

Broadcom Software has exposed Clipminer, a crypto-mining Trojan that also hijacks clipboard data to steal cryptocurrency, potentially earning operators at least $1.7 million. Symantec describes Trojan.Clipminer as bearing similarities to KryptoCibule and notes its Tor-enabled, downloader-heavy infection chain spread via cracked software.
#Clipminer #KryptoCibule #Tor #OnionService #Bitcoin #Ethereum #XMRig #ClipboardHijacking

Keypoints

  • Clipminer is a crypto-mining Trojan (Trojan.Clipminer) that also hijacks clipboard content to redirect cryptocurrency transactions.
  • It appears to be spread through Trojanized downloads of cracked or pirated software and arrives as a self-extracting WinRAR archive dropping a packed downloader DLL with a CPL extension.
  • The malware connects to the Tor network to fetch its components and to communicate with its operators, including sending machine data to an Onion Service.
  • Clipboard hijacking involves replacing wallet addresses in the clipboard with attacker-controlled addresses, with thousands of wallet addresses embedded in the malware.
  • Operating funds include Bitcoin and Ethereum, with evidence pointing to cryptocurrency tumblers used to obscure the trail, contributing to an estimated $1.7 million in gains from clipboard theft alone.
  • Persistence is achieved via RunOnceEx registry keys and scheduled tasks, and the loader drops into carefully named directories to avoid detection.
  • The malware harvests system information, captures screenshots, and uses XMRig (or other miners) to mine when the machine is idle or underutilized, potentially leveraging GPUs as needed.

MITRE Techniques

  • [T1189] Drive-by Compromise – Spread via Trojanized downloads of cracked or pirated software. β€˜spread via Trojanized downloads of cracked or pirated software’
  • [T1090] Proxy – Use of Tor to retrieve components and communicate with C2. β€˜The malware then connects to the Tor network.’
  • [T1115] Clipboard Data – Intercept and replace wallet addresses in clipboard. β€˜The malware then copies the clipboard content and replaces addresses with wallets controlled by the attacker.’
  • [T1082] System Information Discovery – Collect machine details for exfiltration. β€˜It then collects details from the affected computer, as shown in the following example.’
  • [T1113] Screen Capture – Capture desktop screenshots. β€˜1920:1200:[DESKTOP_SCREENSHOT_AS_BASE64_ENCODED_PNG]’
  • [T1496] Resource Hijacking – Mine cryptocurrency using XMRig when the machine is idle. β€˜Whenever the malware determines that a machine is not in use, it starts the XMRig cryptocurrency miner.’
  • [T1053] Scheduled Task – Create scheduled tasks for persistence. β€˜It creates scheduled tasks … to execute the load point for persistence.’

Indicators of Compromise

  • [File hash] File hash – bd48b5da093a37cfa5e3929c19ac06ce711bd581bc49040e68d2ba0e5610bf71 (Dropper)
  • [File hash] File hash – 1d31bea6a065fa20cf41861d21b7ea39979d40126c800ebc87d07adb41fe03f4 (Downloader)
  • [File hash] File hash – f49a5a0f2397609a3fb97728b5a997eb77cfa1b529188403fb5e8adaeac1860b (Packed load point)
  • [File hash] File hash – 12e6883046e2c92cbe3b5706ea7f1181b44512f179c7f04e88e75f3f6e392a48 (Downloader)
  • [File name] rhnoiniye_ni.dll – Packed load point (example file name)
  • [File name] imsgt_dvepr.dll – Used in RegAsm.dll path (example file name)
  • [URL] http://[HOST_IP_AND_PORT]/tor/status-vote/current/consensus.z – Tor consensus data fetch URL
  • [Onion Service] miwia5zo4oxcj7n6:11472 – Example Onion Service endpoint
  • [Onion Service] 6lmt3ott62q5pwae:52403 – Example Onion Service endpoint
  • [IP Address] 94.75.205.148 – Miner pool endpoint observed in command line
  • [IP Address] 179.60.146.9 – Another miner pool endpoint observed in command line

Read more: https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/clipminer-bitcoin-mining-hijacking