Demystifying PKT and Monero Cryptocurrency deployed on MSSQL servers

Feb. 21, 2025, 3:29 p.m.

Description

This analysis examines a recent cryptocurrency mining operation targeting MSSQL servers, focusing on PKT Classic and Monero cryptocurrencies. The attack exploits vulnerabilities to deploy mining tools, including PacketCrypt for PKT and XMRIG for Monero. The process involves using Windows utilities and PowerShell scripts to download and execute malicious files. The miners consume significant system resources, potentially degrading performance and causing hardware wear. The attackers utilize GitHub repositories, obfuscation techniques, and multi-stage attacks to evade detection. The article provides details on the attack chain, wallet information, and file analysis, highlighting the sophisticated nature of the operation. Mitigation strategies include regular software updates, strong authentication measures, and robust antivirus protection.

Date

  • Created: Feb. 20, 2025, 1:44 p.m.
  • Published: Feb. 20, 2025, 1:44 p.m.
  • Modified: Feb. 21, 2025, 3:29 p.m.

Attack Patterns

  • PacketCrypt
  • XMRIG
  • T1588.001
  • T1074.001
  • T1053.005
  • T1059.001
  • T1547.001
  • T1497
  • T1070.004
  • T1562.001
  • T1204.002
  • T1082
  • T1057
  • T1105
  • T1496
  • T1083
  • T1055
  • T1036
  • T1140
  • T1027