Heimdal Security Blog

New Golang Version: the Mining Process Increased By 15%

The new Golang version wreaks havoc in the world of crypto mining worms. The fresh variant of the Golang crypto worm is constructed on XMRig. Its goal is to target certain machines and exploit web vulnerabilities by further deploying Monero-mining malware. What’s more is that the mining process becomes more efficient as a result of this, being accelerated by 15% by the payload binaries.

New Golang Version Based on XMRig: What Is XMRig?

XMRig is a term related to cryptocurrency. It is basically a miner that mines the Monero cryptocurrency via a compromised computer. The goal is to make lots of money. What can it do to a computer? Well, it can severely affect its capabilities, making it overheat or maybe not run properly, because it uses supplementary resources.

How Does the New Golang Version Work?

Uptycs researchers have released a report where they detail how the new Golang version works and what are its targets.

The new Golang version follows the below steps:

According to Cyware, the XMRig that was changed targets hardware. Threat actors used XMRig based adjusted binaries. What can the changed miner do is that it has the capabilities to disable the hardware prefetcher. This is how the increase of 15% in speed is accomplished.

Xmrig miners use the RandomX algorithm which generates multiple unique programs that are generated by data selected from the dataset generated from the hash of a key block. The code to be run inside the VM is generated randomly and the resultant hash of its outcome is used as proof of work.

Source

Cryptocurrency cyberattacks have actually increased recently. Let’s look at Poly Network who has recently lost the fabulous sum of $611 million in a grand cryptocurrency cyberattack. The matter of crypto hacking is supported also by the statistics released by FTC in May, where losses of $80 Million were reported.