Look anywhere in the news today and it’s hard to miss coverage about WannaCry, the SMB exploit-loving ransomware that wormed its way into all our hearts. This piece of malware certainly proved a few points about the current state of cyber security – namely that patch management, network segmentation, asset management and perimeter defense are all areas that need to be taken more seriously.

In addition, however, while attempting to capture new samples of WannaCry in the wild over the weekend, a surprising discovery was made by security researchers: a similar piece of malware was already on the loose and had been performing its nefarious duties in a much less intrusive manner. More surprisingly, it had been active since mid-April, weeks before the more recent WannaCry outbreak. This malware was part of a more traditional botnet intended to use its victims to mine cryptocurrency, and it may have unintentionally taken the edge off of what WannaCry otherwise could have done.

This malware is the Adylkuzz cryptocurrency mining botnet and it spread through the same one-two punch of EternalBlue/DoublePulsar that WannaCry utilized. Instead of encrypting a victim’s files and holding them for ransom this malware simply eats resources on a machine to mine Monero cryptocurrency.  The mining software uses spare processor cycles and memory to perform difficult computations. In addition to starting this mining process, the DoublePulsar payload delivered by the botnet also adds a firewall rule to block port 445 access, the SMB port that was used to infect the victim with this Adylkuzz botnet.

Since both the mining process and addition of a single firewall rule are relatively benign actions to a victim, the only real symptoms of infection would be a slightly sluggish workstation or server and potential loss of file shares. This minimal impact is probably what allowed the botnet to operate for weeks without detection. Additionally, its actions probably prevented the WannaCry epidemic from being as bad as it could have been since the victims of Adylkuzz could not be infected because the required port was no longer open.

More than 20 active exploitation hosts and more than a dozen C2 servers have been identified since discovery over the weekend, though there are probably additional exploitation/C2 servers remaining to be found.

As the dust begins to settle from this outbreak of infections a few questions remain:

  • What other malware has been utilizing these leaked exploits that may have gone unnoticed?
  • How will others change them to increase their usefulness?
  • What will organizations change to ensure that the next major release of exploits doesn’t result in a similar outcome?

Threat Research

Thanks to the analysis of Adylkuzz provided by Kaffeine and others we can provide information about the following IOCs:


