Bitcoin Warns Of State Attack In Binaries

John jnn at synfin.org
Thu Aug 18 03:50:28 PDT 2016


At work I've seen a Bitcoin miner trojan (it's a Windows nullsoft exe masked as a .scr file wrapped up in a file called info.zip) trying to propagate itself through the couple of ftp servers we have open to the world, one of which has a few places that the anonymous guest user can dump (but not list or download) files....

All the attacks have come within the past two weeks from IP addresses all over India....

I don't have the sha256 at hand to send the virustotal link but it's this fucker:

https://brica.de/alerts/alert/public/1004599/obfuscated-bitcoin-miner-propagates-through-ftp-using-password-dictionary/

Luckily no users have been infected :). (AFAICT && I fucking hope & pray)


John

On August 18, 2016 2:23:06 AM EDT, grarpamp <grarpamp at gmail.com> wrote:
>https://bitcoin.org/en/alert/2016-08-17-binary-safety
>0.13.0 Binary Safety Warning
>17 August 2016
>Summary
>
>Bitcoin.org has reason to suspect that the binaries for the upcoming
>Bitcoin Core release will likely be targeted by state sponsored
>attackers. As a website, Bitcoin.org does not have the necessary
>technical resources to guarantee that we can defend ourselves from
>attackers of this calibre. We ask the Bitcoin community, and in
>particular the Chinese Bitcoin community to be extra vigilant when
>downloading binaries from our website.
>
>In such a situation, not being careful before you download binaries
>could cause you to lose all your coins. This malicious software might
>also cause your computer to participate in attacks against the Bitcoin
>network. We believe Chinese services such as pools and exchanges are
>most at risk here due to the origin of the attackers.
>Mitigation
>
>The hashes of Bitcoin Core binaries are cryptographically signed with
>this key.
>
>We strongly recommend that you download that key, which should have a
>fingerprint of 01EA5486DE18A882D4C2684590C8019E36C2E964. You should
>securely verify the signature and hashes before running any Bitcoin
>Core binaries. This is the safest and most secure way of being
>confident that the binaries you’re running are the same ones created
>by the Core Developers.

-- 
Sent from my Android device with K-9 Mail. Please excuse my brevity.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: text/html
Size: 2921 bytes
Desc: not available
URL: <https://lists.cpunks.org/pipermail/cypherpunks/attachments/20160818/5e1060dd/attachment-0002.txt>


More information about the cypherpunks mailing list