• Cyber Security
    • Ransomware Prevention
    • Ransomware Removal
    • Ransomware File Recovery
    • Ransomware Types
  • Ransomware Services
    • Ransomware Removal
    • Ransomware File Recovery
  • News
  • Tutorials
  • Ransomware TV

Cryptocurrency Mining Farms in China are Victim of Ransomware

March 29, 2019Simeon Georgiev

Most of the worlds cryptocurrency mining farms are located in China and now the target is the bitcoin mining industry. There have been reports of malicious crimes and spread of ransomware previously, but this time around the location of the mining rigs is being compromised and it is one that contains a huge percentage of the Bitcoin blockchain’s hash power. This ransomware called ‘hAnt’ has been detected previously, but it targets a variety of mining rigs including Bitmain‘s Antminer S9, T9 and L3 and Avalon equipment. Although its origin and propagation is still unclear, it surely seems to be affecting the economy as the mining industry has weakened and so have the bitcoin prices.

Similar to the ransomware that recently affected Atlanta, Georgia, ‘hAnt’ encrypts the miners file making it useless and unrecoverable until a crypto sum has been paid in exchange for decryption keys. The only differing fact here is the victim connects to the affected rig and is presented by a cryptic interface that shows the prompt for ransom, but in Mandarin and partly in English. The message is as follows; I am hAnt! I continue to attack your Antminer. As long as you spread the infected machine, my server verifies that there are 10 new IPs and the number of antminers reaches 1,000. I will stop attacking you! Otherwise I will turn off your antminer’s fan and overheat protection, which will cause you to burn your machine or will burn the house.

Decryption tools are only provided once exchange of BTC is made. Not only this, but there is added threat of the ransomware spreading to other servers when the mining rigs are required to download firmware updates. For the hackers, this is a great way of gathering more revenue and knowing a miner wouldn’t be able to pay all upfront, the hackers will resort to spreading the virus on the rest of the servers in a bid to cash in from other miners.

In the event that a miner is unable to pay, he is presented with more threats that concern damage to their physical equipment. This would come as overheating and potentially ruining the victim’s business with obviously no equipment left to use. These malicious viruses seem to be spreading rapidly with more improved versions coming on part of the criminals and it is suggested users be careful and download firmware from their original equipment manufacturers and be educated on cybersecurity as to prevent any risk to their businesses and economy.

Simeon Georgiev
https://www.linkedin.com/in/simeon--georgiev/
I am a Cyber Security Enthusiast from Bulgaria. I like to write about malware and ransomware and global cyber attacks. You can reach me on Twitter @sgeorgiev1995 or Email: [email protected]
Previous post 5 Major Cyber Attacks that Can Take Place Next post Ransomware Attack on 3 Private Universities

Related Articles

NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

January 27, 2018Simeon Georgiev
NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

Ransomware: 4 Types of the Latest Trend in Cybercrimes

February 1, 2018Simeon Georgiev
Ransomware: 4 Types of the Latest Trend in Cybercrimes

NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

February 1, 2018Simeon Georgiev
NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

Latest on Ransomware TV

https://vimeo.com/399908876?loop=0

Recent Posts

  • How to protect your organization against ransomware reinfections
  • AuKill Helps Ransomware Operators Disable EDR and Security Tools
  • AI-ransomware is a real threat, just not a realistic one yet
  • Rorschach is the new speed king in the ransomware space
  • The Role of Supply Chain Breaches in Ransomware Attacks

Stay Protected

Subscribe to our mailing list to get the latest cyber security and ransomware removal articles!

Thank you for subscribing.

Something went wrong.

Navigation

  • Cyber Security
    • Ransomware File Recovery
    • Ransomware Prevention
    • Ransomware Removal
    • Ransomware Types
  • News
  • Tutorials

Ransomware Attacks (Last 6M)

0

Connect & Protect

Facebook
Google+
LinkedIn
YouTube
Vimeo

More

  • BECOME A CONTRIBUTOR

MonsterCloud Reviews

© 2020 MonsterCloud.com. All Rights Reserved.