Security News

Cybersecurity news aggregator

MEDIUM Attacks SC Media

Cryptomining campaign avoids root access to evade detection

  • What: Cryptomining campaign evades detection by avoiding root access
  • Impact: Compromised Linux servers may be used for cryptocurrency mining without detection
Read Full Article →

Malware Cryptomining campaign avoids root access to evade detection July 31, 2026 Share By SC Staff (Adobe Stock) A cryptomining operation is deliberately avoiding root access on compromised Linux servers, instead impersonating low-privileged users to bypass security alerts, as reported by Infosecurity Magazine. The campaign, identified in May 2026 by Group-IB, uses a modified XMRig miner. After gaining initial access through a third-party relationship and escalating to root, attackers abuse Linux Pluggable Authentication Modules (PAM) to assume the identities of standard accounts without needing passwords. This tactic creates a "forensic smokescreen" by scattering activity and persistence mechanisms across unmonitored accounts. The attackers also disable core logging services and tamper with authentication logs, leaving minimal traces of their actions. To further evade detection, the malware employs process masquerading, spoofing legitimate process names like "ssh", and uses a Java/Agent user agent for its mining traffic to blend in with normal web application flows. The implant deletes its own binary from disk after execution, residing entirely in memory, which circumvents conventional disk scans. It also terminates competing miners and uses layered XOR keys to conceal its configuration. Researchers recommend forwarding logs in real-time to an external, tamper-proof system and hunting for transient artifacts like mutexes to detect such sophisticated threats. Source: Infosecurity Magazine SC Staff Related Malware Flying Eagle Android RAT source code circulates on Telegram SC Staff July 29, 2026 The Flying Eagle framework is being distributed as a fake "公安一网通办" Public Security service application targeting Android users in China. Malware Italian organizations targeted by 148 ransomware attacks in first half of 2026 SC Staff July 28, 2026 Italian organizations faced 148 confirmed ransomware attacks in the first half of 2026, with the manufacturing sector being the most frequently targeted. Malware Malicious Steam workshop map delivered malware to MECCHA CHAMELEON players SC Staff July 28, 2026 As outlined in Cyber Insider, a malicious Steam Workshop map for the game MECCHA CHAMELEON exploited a vulnerability in the game's mod-loading system to deliver malware to players' computers. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Adware You can skip this ad in 5 seconds

Share this article