A Turkish-based cryptocurrency mining malware campaign has been detected called Nitrokod, that infected machines across 11 countries with an XMRig crypto miner.
The malware operators leverage popular software programs available for download on free software sites, such as Softpedia. To avoid detection, the threat actors separate any malicious activity from the downloaded fake software. The software also appears quite easily in Google search results when you search for “Google Translate Desktop download.”
The applications are advertised as “100 clean” via various banners while in truth they are trojanized. The downloads also contain a delayed mechanism that unleashed a long multi-stage infection ending with a crypto miner malware.
Once after the installation, the attackers delayed the infection process for weeks and deleted traces from the original installation. This allowed the campaign to successfully operate under the radar for years.
These are the steps the Nitrokod attacker followed to avoid detection:
- Executing the malware almost a month after the Nitrokod program was installed.
- Delivering the payload after 6 earlier stages of infected programs.
- A continuous infection chain initiated after a long delay using a scheduled task mechanism, giving the attackers time to clear the evidence.
Nearly all detected Nitrokod campaigns share the same infection chain, starting with the installation of a freely downloaded, trojanized app and ending with the miner’s installation.
Once the user launches the new software, an actual Google Translate application is installed. In addition, an updated file is dropped which starts a series of four droppers until the actual malware is dropped. Once executed, the malware connects to its command-and-control server to receive a configuration for the XMRig crypto miner and start the mining process.
To clean an infected machine, follow these steps.
- Remove the following files on system32:
- Any file starting with chainlink.
- Remove the updater.
- Remove the folder C:\ProgramData\Nitrokod.
- Remove malicious schedule tasks.
Indicators of Compromise