Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

Here is why Strategy's dividend-paying crypto stock is crashing to near-historic lows

June 16, 2026

HashKey Chain Partners Morpho to Blend Compliance and DeFi for Institutional CeDeFi and RWA Lending

June 16, 2026

Kraken Brings Regulated Perpetual Futures Onshore to US Users

June 16, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»Chaos RAT Used to Enhance Linux Cryptomining Attacks
Chaos RAT Used to Enhance Linux Cryptomining Attacks
Security

Chaos RAT Used to Enhance Linux Cryptomining Attacks

October 14, 2023No Comments2 Mins Read

The Chaos remote administrative tool (RAT) has been used to improve the efficiency of cryptocurrency mining attacks against Linux systems.

The findings from Trend Micro security researchers were detailed in an advisory published on Sunday.

“We’ve previously written about cryptojacking scenarios involving Linux machines and specific cloud computing instances being targeted by threat actors active in this space, such as TeamTNT,” the security experts wrote.

During their investigative efforts, Trend Micro said they found that the attacker tactics were similar, even if they involved different threat actors.

“The initial phase saw attackers trying to kill off competing malware, security products, and other cloud middleware. This was followed by routines for persistence and payload execution, which in most cases is a Monero (XMR) cryptocurrency miner,” reads the technical write-up.

For more sophisticated threats, Trend Micro said they have also observed capabilities that allowed infection on more devices.

“In November 2022, we intercepted a threat that had a slightly different routine and incorporated an advanced RAT named Chaos […] which is based on an open-source project.”

In the newly observed attacks, the main downloader script and further payloads were hosted in different locations to ensure that the campaign remained active and kept on spreading.

During this malicious campaign, the scripts spotted by Trend Micro showed that the main server, which was also used for downloading payloads, appeared to be located in Russia.

From a technical standpoint, the Chaos RAT is a Go-compiled binary with several functions, including executing reverse shells, downloading and uploading files, and taking screenshots, among others.

See also  88 people charged over 12 crypto wrench attacks in France

“On the surface, the incorporation of a RAT into the infection routine of a cryptocurrency mining malware might seem relatively minor,” Trend Micro wrote.

“However, given the tool’s array of functions and the fact that this evolution shows that cloud-based threat actors are still evolving their campaigns, it is important that both organizations and individuals stay extra vigilant when it comes to security.”

The Trend Micro advisory comes roughly two months after decentralized finance (DeFi) platform Moola Market confirmed it suffered a security incident leading to a loss of up to $9m worth of cryptocurrency.

Source link

attacks Chaos Cryptomining Enhance Linux RAT

Related Posts

India’s NHRC Raises Alarm Over Digital Arrest Scams

June 16, 2026

Rokarolla Trojan Combines Banking Fraud With Device Surveillance

June 16, 2026

Pyra to Cease Operations Following Drift Hack, Launches Fund Withdrawal Portal

June 16, 2026

Oklahoma Raises Alarm Over Fake Crypto Returns

June 16, 2026
Top Posts

Novo Nordisk Extends Slide After Announcing Price-Cuts For Blockbuster Obesity Drugs

February 24, 2026

United States Edge Computing for Autonomous Vehicles Market to hit US$ 11.7 Billion by 2032 | North America leads with 30% share | Top Companies – NVIDIA Corporation, Intel Corporation (Mobileye), Qualcomm Technologies, Inc.

February 6, 2026

South Korea’s Financial Regulator Warns Investors of Surging Memecoin Scams on Decentralized Exchanges

June 15, 2026

Type above and press Enter to search. Press Esc to cancel.