Technology
BlueKeep mass attacking vulnerable machines
San Francisco, Nov 4
The "BlueKeep" remote code execution vulnerability, which could have an effect similar to the WannaCry bug from 2017, is currently attacking vulnerable machines that are apparently compromised for cryptocurrency mining purposes, according to media reports.
The BlueKeep vulnerability exists in unpatched versions of Windows Server 2003, Windows XP, Windows Vista, Windows 7, Windows Server 2008 and Windows Server 2008 R2.
According to security researcher Kevin Beaumont, several honeypots in his EternalPot RDP honeypot network started to crash and reboot.
They've been active for almost half a year and this is the first time they came down. For some reason, the machines in Australia did not crash, the researcher said in a tweet, Bleeping Computer reported on Sunday.
Security researchers, including Beaumont who originally named the vulnerability and Marcus Hutchins, also known as "MalwareTech", who was responsible for hitting the kill switch that stopped the WannaCry bug, have confirmed that a widespread BlueKeep exploit attack is now currently underway.
Hutchins was quoted as saying by the Wired that "BlueKeep has been out there for a while now. But this is the first instance where I've seen it being used on a mass scale."
Interestingly, BlueeKeep has the ability to spread itself from one machine to another, while the attackers are searching for vulnerable unpatched Windows systems that have Remote Desktop Services (RDP) 3389 ports exposed to the Internet.
For now though, this looks like being an attack campaign with a cryptocurrency miner payload, according to Forbes.
The BlueKeep vulnerability exists in unpatched versions of Windows Server 2003, Windows XP, Windows Vista, Windows 7, Windows Server 2008 and Windows Server 2008 R2.
According to security researcher Kevin Beaumont, several honeypots in his EternalPot RDP honeypot network started to crash and reboot.
They've been active for almost half a year and this is the first time they came down. For some reason, the machines in Australia did not crash, the researcher said in a tweet, Bleeping Computer reported on Sunday.
Security researchers, including Beaumont who originally named the vulnerability and Marcus Hutchins, also known as "MalwareTech", who was responsible for hitting the kill switch that stopped the WannaCry bug, have confirmed that a widespread BlueKeep exploit attack is now currently underway.
Hutchins was quoted as saying by the Wired that "BlueKeep has been out there for a while now. But this is the first instance where I've seen it being used on a mass scale."
Interestingly, BlueeKeep has the ability to spread itself from one machine to another, while the attackers are searching for vulnerable unpatched Windows systems that have Remote Desktop Services (RDP) 3389 ports exposed to the Internet.
For now though, this looks like being an attack campaign with a cryptocurrency miner payload, according to Forbes.
1 hour ago
Over 40,000 Americans return from Middle East evacuations
1 hour ago
Oil nears $90 as Iran war jolts markets
1 hour ago
PALESTINE ‘36
1 hour ago
Shri. Koshy O. Thomas received
1 hour ago
Canada: Absence of arrests in murder of Khalistani critic fuels speculation and outrage
3 hours ago
Steep US tariffs strained ties with India, stalled momentum within Quad: Senate report
3 hours ago
Death, fire, and fury will rain upon Iran if flow of oil is stopped through Strait of Hormuz: US
3 hours ago
President Trump has specific mission to accomplish, Iran war will not become endless: Hegseth
4 hours ago
'Today will be yet again our most intense day of strikes inside Iran': US War Secy as West Asia conflict enters its 11th day
9 hours ago
Munmun Dutta calls out ‘disgusting' acts of Indians at tourist spots: Such acts attract racism abroad
9 hours ago
Lisa Ray says midlife is not a crisis but ‘the most important act of a woman’s life’
9 hours ago
R J Balaji trashes rumours that Suriya's 'Karuppu' is to release on April 10; promises update on release shortly
9 hours ago
When Govinda said ‘men are weak without women’ citing Lord Shiva’s example
