New Monero mining malware discovered in Google Play

In November 2017, we detected a strain of malware known as JSMiner in Google Play. The Monero cryptomining capabilities were discovered inside the gaming application Cooee. At the time of discovery, we forecasted a rise in mobile mining malware as atta…

Greedy cybercriminals host malware on GitHub

Cybercriminals are aggressively uploading cryptocurrency mining malware to GitHub. The cybercriminals fork other projects, which on Github means producing a copy of someone else’s project, to build upon the project or to use as a starting point and subsequently push a new commit with the malware to the project. The projects which have been forked appear to be chosen at random. A list of affected GitHub repositories can be found at the bottom of this blog post.

Botnet at large: Avast blocks Smominru miner

The good news is that Avast users are protected against cryptomining, which includes the current threat terrorizing the world’s Windows servers and computers. The Smominru botnet has torn through hundreds of thousands of servers and computers alike, hijacking their CPU power to mine the cryptocurrency Monero. ZDNet reports that the Smominru botnet mines 24 Monero ($8,500) a day, with a net total to date of 8,900 Monero ($2.8M – $3.6M).

Meltdown and Spectre: Yes, your device is likely vulnerable

Details have emerged this week regarding two different—and both substantial—security flaws in almost every computer processor in use today. This affects Windows, Mac, Linux, Android, and iOS. It’s important to note that as of yet, no malware or cyberattack has been associated with these flaws, but now that the information is in the public domain, that could change. Either of the flaws could lead to your computer’s memory being compromised, which means sensitive data—passwords, photos, credit card details—can be accessed and stolen. Here’s a breakdown of the two vulnerabilities: