Technology
BlueKeep mass attacking vulnerable machines
San Francisco, Nov 4
The "BlueKeep" remote code execution vulnerability, which could have an effect similar to the WannaCry bug from 2017, is currently attacking vulnerable machines that are apparently compromised for cryptocurrency mining purposes, according to media reports.
The BlueKeep vulnerability exists in unpatched versions of Windows Server 2003, Windows XP, Windows Vista, Windows 7, Windows Server 2008 and Windows Server 2008 R2.
According to security researcher Kevin Beaumont, several honeypots in his EternalPot RDP honeypot network started to crash and reboot.
They've been active for almost half a year and this is the first time they came down. For some reason, the machines in Australia did not crash, the researcher said in a tweet, Bleeping Computer reported on Sunday.
Security researchers, including Beaumont who originally named the vulnerability and Marcus Hutchins, also known as "MalwareTech", who was responsible for hitting the kill switch that stopped the WannaCry bug, have confirmed that a widespread BlueKeep exploit attack is now currently underway.
Hutchins was quoted as saying by the Wired that "BlueKeep has been out there for a while now. But this is the first instance where I've seen it being used on a mass scale."
Interestingly, BlueeKeep has the ability to spread itself from one machine to another, while the attackers are searching for vulnerable unpatched Windows systems that have Remote Desktop Services (RDP) 3389 ports exposed to the Internet.
For now though, this looks like being an attack campaign with a cryptocurrency miner payload, according to Forbes.
The BlueKeep vulnerability exists in unpatched versions of Windows Server 2003, Windows XP, Windows Vista, Windows 7, Windows Server 2008 and Windows Server 2008 R2.
According to security researcher Kevin Beaumont, several honeypots in his EternalPot RDP honeypot network started to crash and reboot.
They've been active for almost half a year and this is the first time they came down. For some reason, the machines in Australia did not crash, the researcher said in a tweet, Bleeping Computer reported on Sunday.
Security researchers, including Beaumont who originally named the vulnerability and Marcus Hutchins, also known as "MalwareTech", who was responsible for hitting the kill switch that stopped the WannaCry bug, have confirmed that a widespread BlueKeep exploit attack is now currently underway.
Hutchins was quoted as saying by the Wired that "BlueKeep has been out there for a while now. But this is the first instance where I've seen it being used on a mass scale."
Interestingly, BlueeKeep has the ability to spread itself from one machine to another, while the attackers are searching for vulnerable unpatched Windows systems that have Remote Desktop Services (RDP) 3389 ports exposed to the Internet.
For now though, this looks like being an attack campaign with a cryptocurrency miner payload, according to Forbes.
8 hours ago
Piyush Goyal meets Canadian Minister Maninder Sidhu to seal trade pact soon
9 hours ago
Marathi film ‘Gondhal’ announced as India's official selection for 99th Academy Awards
9 hours ago
Friendship Cup a celebration of cricket, reflects strong India-Afghanistan bond: DDCA chief Jaitley
12 hours ago
ActBlue faces scrutiny over foreign donations
12 hours ago
Kwatra recalls leadership lesson from mentorship under Satya Nadella’s father
15 hours ago
Zee TV’s Sa Re Ga Ma Pa – The Original Icon of Singing Shows is Back with Its Grandest Season Yet; Will Also Stream on ZEE5
15 hours ago
Lust Stories 3 Review: Four Stories. Unusual Desires and Plenty of Surprises
15 hours ago
Joey King: Sandra Bullock's one of the nicest people I’ve ever met in my life
15 hours ago
Upendra’s first look from Teja Sajja's 'Zombie Reddy2 NXT LVL' released!
15 hours ago
Karan Johar and Varun Dhawan to host IIFA Awards 2027 in Abu Dhabi
15 hours ago
Sana Thampi opens up about her first collaboration with Kiran Rao for ‘Lust Stories 3’
15 hours ago
Nivin Pauly pens note of gratitude as his Bethlehem Kudumba Unit's collections go past the Rs 300 crore mark!
15 hours ago
Actor Nani on why he does not want people to call his films pan-Indian!
