• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

Linux Raspberry Pi Devices Being Infected by Cryptocoin "Mining Malware"

Joined
Aug 20, 2007
Messages
20,787 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
If you have your Raspberry Pi setup and have never changed the default password on the standard "pi" user, it's probably time to do so. A new malware has come out that exploits the simple fact several users apparently have never changed this password. Once it installs itself, it exploits the recent rise in value on cryptocurrency (Bitcoin recently topped $3000 per BTC) to mine cryptocoins for the authors benefit. This not only uses almost 100% of your poor Raspberry Pi's limited CPU, but also makes it part of a "mining botnet" that nets the controller money, adding insult to injury. The malware also makes an anonymous proxy on your box, which needless to say is probably not a good thing.




You might think you are safe behind a firewall, but with the rise of IPv6 on many ISPs and the fact that many older firewalls are not IPv6 ready, you may be surprised to find your SSH port is in fact exposed on the internet whether you know it or not via a global IPv6 address, NAT isn't a guarantee anymore, folks. It is in fact best to actually have a strong, non-default password on your box, even if it is just a little ARM-core.

Unfortunately, as Cryptocurrency rises in value and becomes more legitimate, it brings with it both positive, tangible benefits for society, and sadly, criminal fringe elements. I'd argue that the dollar is still the most widely used currency for criminal transactions, but there's more to it than that for certain. Maybe that's a topic for a future editorial? I don't know.

For now, just remember to always be vigilant in system security, as malware is sure to explode more than ever now that people have realized that they can make a profit on your misery.

View at TechPowerUp Main Site
 
Last edited:
Joined
Aug 20, 2007
Messages
20,787 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
Speaking as an experienced miner from ages past, they are almost certainly not mining bitcoin directly. They are mining one of the many CPU-minable coins around (which aren't really even worth electricity usually, but hey, they aren't paying) then trading them for bitcoin, and selling. This probably makes the perpetrators even harder to track since it crosses multiple currency boundaries.
 
Joined
Sep 15, 2015
Messages
1,029 (0.33/day)
Location
Latvija
System Name Fujitsu Siemens, HP Workstation
Processor Athlon x2 5000+ 3.1GHz, i5 2400
Motherboard Asus
Memory 4GB Samsung
Video Card(s) rx 460 4gb
Storage 750 Evo 250 +2tb
Display(s) Asus 1680x1050 4K HDR
Audio Device(s) Pioneer
Power Supply 430W
Mouse Acme
Keyboard Trust
On my raspberry3b i get problems whit instaling updates, error when shuting down, no internet conection, black srean, and my charger blowup.
 

silentbogo

Moderator
Staff member
Joined
Nov 20, 2013
Messages
5,474 (1.44/day)
Location
Kyiv, Ukraine
System Name WS#1337
Processor Ryzen 7 3800X
Motherboard ASUS X570-PLUS TUF Gaming
Cooling Xigmatek Scylla 240mm AIO
Memory 4x8GB Samsung DDR4 ECC UDIMM
Video Card(s) Inno3D RTX 3070 Ti iChill
Storage ADATA Legend 2TB + ADATA SX8200 Pro 1TB
Display(s) Samsung U24E590D (4K/UHD)
Case ghetto CM Cosmos RC-1000
Audio Device(s) ALC1220
Power Supply SeaSonic SSR-550FX (80+ GOLD)
Mouse Logitech G603
Keyboard Modecom Volcano Blade (Kailh choc LP)
VR HMD Google dreamview headset(aka fancy cardboard)
Software Windows 11, Ubuntu 20.04 LTS
And that's when I thought I've heard everything... Crypto-infected raspberry pi :laugh:
You'd think it will be some kind of botnet for DDoS attacks, or scamming AdWords... but cryptomining?!
I'm wondering how many devices do you need to make any profit? 1K? 10K?
 
Joined
Aug 20, 2007
Messages
20,787 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
I'm wondering how many devices do you need to make any profit? 1K? 10K?

Not a whole lot when your cost is 0.

Meaningful profit is another story. It must be fairly widespread to even get anywhere. I'd picture knowing CPU-mining values, 100 devices would probably pull in a buck or so a day minimum. So we can bet it's at least that.
 
Joined
Sep 15, 2015
Messages
1,029 (0.33/day)
Location
Latvija
System Name Fujitsu Siemens, HP Workstation
Processor Athlon x2 5000+ 3.1GHz, i5 2400
Motherboard Asus
Memory 4GB Samsung
Video Card(s) rx 460 4gb
Storage 750 Evo 250 +2tb
Display(s) Asus 1680x1050 4K HDR
Audio Device(s) Pioneer
Power Supply 430W
Mouse Acme
Keyboard Trust
Where did youu buy it ? Are sure it's not a cheap copy ?
Its orginal, all 10 euro chargers is shit and micro usb cables, only playstation haw good one.
 
Joined
May 9, 2012
Messages
8,408 (1.92/day)
Location
Ovronnaz, Wallis, Switzerland
System Name main/SFFHTPCARGH!(tm)/Xiaomi Mi TV Stick/Samsung Galaxy S23/Ally
Processor Ryzen 7 5800X3D/i7-3770/S905X/Snapdragon 8 Gen 2/Ryzen Z1 Extreme
Motherboard MSI MAG B550 Tomahawk/HP SFF Q77 Express/uh?/uh?/Asus
Cooling Enermax ETS-T50 Axe aRGB /basic HP HSF /errr.../oh! liqui..wait, no:sizable vapor chamber/a nice one
Memory 64gb Corsair Vengeance Pro 3600mhz DDR4/8gb DDR3 1600/2gb LPDDR3/8gb LPDDR5x 4200/16gb LPDDR5
Video Card(s) Hellhound Spectral White RX 7900 XTX 24gb/GT 730/Mali 450MP5/Adreno 740/RDNA3 768 core
Storage 250gb870EVO/500gb860EVO/2tbSandisk/NVMe2tb+1tb/4tbextreme V2/1TB Arion/500gb/8gb/256gb/2tb SN770M
Display(s) X58222 32" 2880x1620/32"FHDTV/273E3LHSB 27" 1920x1080/6.67"/AMOLED 2X panel FHD+120hz/FHD 120hz
Case Cougar Panzer Max/Elite 8300 SFF/None/back/back-front Gorilla Glass Victus 2+ UAG Monarch Carbon
Audio Device(s) Logi Z333/SB Audigy RX/HDMI/HDMI/Dolby Atmos/KZ x HBB PR2/Edifier STAX Spirit S3 & SamsungxAKG beans
Power Supply Chieftec Proton BDF-1000C /HP 240w/12v 1.5A/4Smart Voltplug PD 30W/Asus USB-C 65W
Mouse Speedlink Sovos Vertical-Asus ROG Spatha-Logi Ergo M575/Xiaomi XMRM-006/touch/touch
Keyboard Endorfy Thock 75% <3/none/touch/virtual
VR HMD Medion Erazer
Software Win10 64/Win8.1 64/Android TV 8.1/Android 13/Win11 64
Benchmark Scores bench...mark? i do leave mark on bench sometime, to remember which one is the most comfortable. :o
oh well, i am happy i got a Asus Tinkerboard instead, when i got rid of my RPi2 and 3 a while ago ...

the community is smaller than the RPi, the SOC is a less liked one (not liked by KODI/OSMC/LibreElec specifically) ... but hey ... got Android 6.0 and TinkerOS got some sweet updates recently ...

let's hope it does not come to the Tinkerboard (well as it is quite more powerful than a Pi3 ... that may tempt the malware author .... or not ... thanks to the smaller community :laugh: )

Its orginal, all 10 euro chargers is shit and micro usb cables, only playstation haw good one.
i had the official Strontronic RPi charger (tho technically not a charger ... there is nothing to charg on a RPi unless you have a battery on it) and it was not "shit"... although mine did cost more 19€ than 10€ also 5V 2.5A is a minima for the RPi3 i hope your 10€ charger was not under these values, nor did i had any issues you had on my own Pi3
on the other hand when purchased 2 fake RPi3 on Gearbest and Aliexpress for testing purpose (real fake, faked from PCB to the Box, not BananaPi or OrangePi as these are not bad at all) i got some error on updates using Raspbian, heck even OSMC or Libreelec refused to install on it ... :D (thought the SOC was still a Broadcom2837)
 
Joined
Jul 5, 2013
Messages
25,559 (6.47/day)
If you have your Raspberry Pi setup and have never changed the default password on the standard "pi" user, it's probably time to do so.
Such is a good rule of thumb anyway. With RPi based distro's people are not generally using them as a primary computing platform with all their personal info on them, so a simple password other than the default would be enough.
You might think you are safe behind a firewall, but with the rise of IPv6 on many ISPs and the fact that many older firewalls are not IPv6 ready, you may be surprised to find your SSH port is in fact exposed on the internet whether you know it or not via a global IPv6 address, NAT isn't a guarantee anymore, folks.
This is less of a problem than it seems. A simple solution is to turn off IPv6 altogether at the OS and Router levels. ALL ISP's have IPv4 tunneling and will continue to do so for at least the next decade as IPv4 is still very useful and prevalent in the world. IPv6 for the Internet is needed, but not in homes or small business'.
 
Joined
Aug 20, 2007
Messages
20,787 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
This is less of a problem than it seems. A simple solution is to turn off IPv6 altogether at the OS and Router levels. ALL ISP's have IPv4 tunneling and will continue to do so for at least the next decade as IPv4 is still very useful and prevalent in the world. IPv6 for the Internet is needed, but not in homes or small business'.

It's not a huge problem, only a possibility I sought to point out.
 
Top