Technology
BlueKeep mass attacking vulnerable machines
San Francisco, Nov 4
The "BlueKeep" remote code execution vulnerability, which could have an effect similar to the WannaCry bug from 2017, is currently attacking vulnerable machines that are apparently compromised for cryptocurrency mining purposes, according to media reports.
The BlueKeep vulnerability exists in unpatched versions of Windows Server 2003, Windows XP, Windows Vista, Windows 7, Windows Server 2008 and Windows Server 2008 R2.
According to security researcher Kevin Beaumont, several honeypots in his EternalPot RDP honeypot network started to crash and reboot.
They've been active for almost half a year and this is the first time they came down. For some reason, the machines in Australia did not crash, the researcher said in a tweet, Bleeping Computer reported on Sunday.
Security researchers, including Beaumont who originally named the vulnerability and Marcus Hutchins, also known as "MalwareTech", who was responsible for hitting the kill switch that stopped the WannaCry bug, have confirmed that a widespread BlueKeep exploit attack is now currently underway.
Hutchins was quoted as saying by the Wired that "BlueKeep has been out there for a while now. But this is the first instance where I've seen it being used on a mass scale."
Interestingly, BlueeKeep has the ability to spread itself from one machine to another, while the attackers are searching for vulnerable unpatched Windows systems that have Remote Desktop Services (RDP) 3389 ports exposed to the Internet.
For now though, this looks like being an attack campaign with a cryptocurrency miner payload, according to Forbes.
The BlueKeep vulnerability exists in unpatched versions of Windows Server 2003, Windows XP, Windows Vista, Windows 7, Windows Server 2008 and Windows Server 2008 R2.
According to security researcher Kevin Beaumont, several honeypots in his EternalPot RDP honeypot network started to crash and reboot.
They've been active for almost half a year and this is the first time they came down. For some reason, the machines in Australia did not crash, the researcher said in a tweet, Bleeping Computer reported on Sunday.
Security researchers, including Beaumont who originally named the vulnerability and Marcus Hutchins, also known as "MalwareTech", who was responsible for hitting the kill switch that stopped the WannaCry bug, have confirmed that a widespread BlueKeep exploit attack is now currently underway.
Hutchins was quoted as saying by the Wired that "BlueKeep has been out there for a while now. But this is the first instance where I've seen it being used on a mass scale."
Interestingly, BlueeKeep has the ability to spread itself from one machine to another, while the attackers are searching for vulnerable unpatched Windows systems that have Remote Desktop Services (RDP) 3389 ports exposed to the Internet.
For now though, this looks like being an attack campaign with a cryptocurrency miner payload, according to Forbes.
3 minutes ago
The petrol pumps in the state will remain closed today from 6 AM to 12 noon.
18 minutes ago
Israeli PM Netanyahu, US Prez Biden discuss Gaza hostage deal
21 minutes ago
Two Myanmar nationals held in Mizoram with huge haul of foreign currency
21 minutes ago
50 lakh people take dip in Sangam a day ahead of Paush Purnima
22 minutes ago
Collective efforts needed to inculcate sense of oneness: Manipur CM
23 minutes ago
There is no water; firefighters are struggling to control the wildfire.
23 minutes ago
J&K L-G, CM Omar extend warm wishes on Lohri, Makar Sankranti, emphasises togetherness, prosperity
25 minutes ago
Youth must transform ideas into reality for a Viksit Bharat: Jitendra Singh
25 minutes ago
Steve Jobs' wife Laurene Powell prays at UP temple, to visit Maha Kumbh
27 minutes ago
After 7.93 pc reduction in GHG emissions, India committed to sustainable future: Centre
28 minutes ago
Once monthly injectables to become future therapeutic options for obesity: Report
29 minutes ago
Study finds petrochemical industries behind winter ozone pollution
30 minutes ago
Cambodia records 46 per cent drop in dengue cases in 2024