Adylkuzz
Adylkuzz is a type of malware that primarily functions as a cryptocurrency miner. It exploits vulnerabilities in computer systems to mine Monero, a type of cryptocurrency, without the user's knowledge. The malware gained attention for its use of the EternalBlue exploit, which was also utilized by the infamous WannaCry ransomware. Adylkuzz operates by infecting computers and using their processing power to mine cryptocurrency, which is then sent to the attacker's wallet. As of October 2023, Adylkuzz remains a notable example of how cybercriminals leverage existing vulnerabilities to conduct illicit activities.
Overview
Adylkuzz is a cryptocurrency mining malware that targets Windows operating systems. It exploits the EternalBlue vulnerability, which was initially discovered by the United States National Security Agency (NSA) and later leaked by the Shadow Brokers hacking group. The malware is designed to mine Monero, a privacy-focused cryptocurrency, by utilizing the infected system's resources. This results in degraded performance for the user, as the malware consumes significant processing power and network bandwidth.
History
Adylkuzz was first identified in May 2017, shortly after the WannaCry ransomware attack. Researchers from Proofpoint, a cybersecurity company, discovered the malware while investigating the spread of WannaCry. Unlike WannaCry, which demanded a ransom from victims, Adylkuzz operates silently in the background, making it less noticeable. The malware's use of the EternalBlue exploit allowed it to spread rapidly across vulnerable systems, particularly those that had not applied the necessary security patches.
Technical characteristics
Adylkuzz is characterized by its use of the EternalBlue exploit, which targets a vulnerability in the Server Message Block (SMB) protocol of Windows operating systems. Once the malware gains access to a system, it downloads and installs a cryptocurrency mining software. The mining software then begins to mine Monero, using the infected system's processing power. The mined cryptocurrency is sent to the attacker's wallet, providing them with financial gain at the expense of the victim's system performance.
Infection vector
The primary infection vector for Adylkuzz is the EternalBlue exploit, which targets the SMB protocol. This exploit allows the malware to spread across networks by exploiting unpatched systems. Once a system is infected, Adylkuzz scans the network for other vulnerable machines, allowing it to propagate quickly. The malware does not require user interaction to spread, making it particularly effective in environments where security patches have not been applied.
Notable campaigns
Adylkuzz was most active in May 2017, coinciding with the WannaCry ransomware attack. During this period, the malware infected thousands of systems worldwide, primarily targeting unpatched Windows machines. The campaign highlighted the importance of timely security updates, as many of the affected systems had not applied the necessary patches to protect against the EternalBlue exploit. While the malware's activity has decreased since its initial outbreak, it remains a concern for systems that have not been updated.
Detection and mitigation
Detecting Adylkuzz can be challenging due to its stealthy nature. However, signs of infection include decreased system performance and increased network activity. Security software can help detect and remove the malware by identifying the mining software and its associated processes. To mitigate the risk of infection, users should ensure that their systems are up-to-date with the latest security patches. Additionally, network administrators should disable the SMB protocol on systems where it is not needed and implement firewalls to block unauthorized access.