Technology
BlueKeep mass attacking vulnerable machines
San Francisco, Nov 4
The "BlueKeep" remote code execution vulnerability, which could have an effect similar to the WannaCry bug from 2017, is currently attacking vulnerable machines that are apparently compromised for cryptocurrency mining purposes, according to media reports.
The BlueKeep vulnerability exists in unpatched versions of Windows Server 2003, Windows XP, Windows Vista, Windows 7, Windows Server 2008 and Windows Server 2008 R2.
According to security researcher Kevin Beaumont, several honeypots in his EternalPot RDP honeypot network started to crash and reboot.
They've been active for almost half a year and this is the first time they came down. For some reason, the machines in Australia did not crash, the researcher said in a tweet, Bleeping Computer reported on Sunday.
Security researchers, including Beaumont who originally named the vulnerability and Marcus Hutchins, also known as "MalwareTech", who was responsible for hitting the kill switch that stopped the WannaCry bug, have confirmed that a widespread BlueKeep exploit attack is now currently underway.
Hutchins was quoted as saying by the Wired that "BlueKeep has been out there for a while now. But this is the first instance where I've seen it being used on a mass scale."
Interestingly, BlueeKeep has the ability to spread itself from one machine to another, while the attackers are searching for vulnerable unpatched Windows systems that have Remote Desktop Services (RDP) 3389 ports exposed to the Internet.
For now though, this looks like being an attack campaign with a cryptocurrency miner payload, according to Forbes.
The BlueKeep vulnerability exists in unpatched versions of Windows Server 2003, Windows XP, Windows Vista, Windows 7, Windows Server 2008 and Windows Server 2008 R2.
According to security researcher Kevin Beaumont, several honeypots in his EternalPot RDP honeypot network started to crash and reboot.
They've been active for almost half a year and this is the first time they came down. For some reason, the machines in Australia did not crash, the researcher said in a tweet, Bleeping Computer reported on Sunday.
Security researchers, including Beaumont who originally named the vulnerability and Marcus Hutchins, also known as "MalwareTech", who was responsible for hitting the kill switch that stopped the WannaCry bug, have confirmed that a widespread BlueKeep exploit attack is now currently underway.
Hutchins was quoted as saying by the Wired that "BlueKeep has been out there for a while now. But this is the first instance where I've seen it being used on a mass scale."
Interestingly, BlueeKeep has the ability to spread itself from one machine to another, while the attackers are searching for vulnerable unpatched Windows systems that have Remote Desktop Services (RDP) 3389 ports exposed to the Internet.
For now though, this looks like being an attack campaign with a cryptocurrency miner payload, according to Forbes.
7 minutes ago
Upset Hindus urge Shein Group to apologize & withdraw Lord Ganesh doormat
8 minutes ago
President Droupadi Murmu hosts Women’s ODI WC-winning Indian team at Rashtrapati Bhavan
9 minutes ago
Heartbroken woman techie held for fake bomb threats to B'luru schools
9 minutes ago
Chhattisgarh: Kamala Sodi, woman Maoist with Rs 17 lakh bounty, surrenders
10 minutes ago
Bhagalpur’s Class 7 student prepares sketch of PM Modi for warm welcome
10 minutes ago
Patna Admin clarifies: Voter slip not mandatory, 12 alternate IDs valid for Bihar polls
11 minutes ago
Vice President Radhakrishnan honours Chhattisgarh’s finest at Rajyotsav ceremony
13 minutes ago
Kerala Police track down man on the run, after 2 decades
13 minutes ago
Viral video claiming Mi-17 helicopter shot down in Kashmir is fake, says PIB
14 minutes ago
Man dies of 'delay' in angioplasty at Thiruvananthapuram Medical College
15 minutes ago
History-sheeter stabbed in full public view in Hyderabad succumbs to injuries
17 minutes ago
Bihar polls: CM Nitish Kumar casts his vote in Bakhtiyarpur, shows inked finger
17 minutes ago
Thiruvananthapuram Corporation polls poised for three-way contest
