Despite the profitability of ransomware there is a good reason why mining malware is thriving

Posted by    on   Sep 15, 2017

When, a few years ago, a friend and I were analysing a rather large botnet and we saw some network traffic indicating that it was engaged in Bitcoin mining, we felt rather disappointed: using malware to mine for cryptocurrencies is about as basic as it gets. It is the digital equivalent of breaking into someone's house, stealing all their books and furniture, and then burning them to use as fuel.

That was four years ago, but miners continue to thrive: Kaspersky researchers say they have seen 1.65 million infections involving mining software in 2017 alone, while ESET writes about how some malicious ads use JavaScript to mine cryptocurrencies in the browser.

Cryptocurrencies (or 'crypto', if you want to annoy the cryptography community) have seen huge increases in their value, but even at the current rates, why would someone use a compromised PC for mining purposes, when there are Bitcoin farms that use dedicated hardware to mine far more efficiently? Wouldn't every calculating cybercriminal switch to the far more profitable ransomware instead, preferring hundreds of dollars (even if not every victim ends up paying) over mere pennies?

The probable answer lies in the global distribution of malware. Cybercriminals have discovered that a few hundred dollars is the 'right' amount for a ransom: enough to generate them a good income, yet affordable for most users who really want their files back. But this is only true for users living in Western countries, on Western incomes. And the Western world is not where the majority of malware infections exist.

In its State of Malware Report (pdf) from the beginning of this year, Malwarebytes writes that almost two-thirds of botnet detections are in Asia or Africa, compared with barely more than ten per cent of ransomware detections.

 

malwarebytes_malware_continents.png

Source: Malwarebytes.


The first stage of a malware infection is often a 'loader', whose sole task is to download the actual payload. A number of factors are taken into consideration when determining which malware to download, and geographic location is prominent among them. Thus the same malicious spam email can lead to ransomware in one country and to Bitcoin mining malware in another, where ransomware is not likely to yield sufficient gains.

As human beings, cybercriminals often don't make fully rational decisions. But when it comes to using their botnets to mine for malware, there really is a simple explanation.

twitter.png
fb.png
linkedin.png
hackernews.png
reddit.png

 

Latest posts:

VB2018 paper: Lazarus Group: a mahjong game played with different sets of tiles

The Lazarus Group, generally linked to the North Korean government, is one of the most notorious threat groups seen in recent years. At VB2018 ESET researchers Peter Kálnai and Michal Poslušný presented a paper looking at the group's various…

Book your VB2019 ticket now for a chance to win a ticket for BSides London

Virus Bulletin is proud to sponsor this year's BSides London conference, which will take place next week, and we have a number of tickets to give away.

First 11 partners of VB2019 announced

We are excited to announce the first 11 companies to partner with VB2019, whose support will help ensure a great event.

VB2018 paper: Fake News, Inc.

A former reporter by profession, Andrew Brandt's curiosity was piqued when he came across what appeared at first glance to be the website of a small-town newspaper based in Illinois, but under scrutiny, things didn’t add up. At VB2018 he presented a…

Paper: Alternative communication channel over NTP

In a new paper published today, independent researcher Nikolaos Tsapakis writes about the possibilities of malware using NTP as a covert communication channel and how to stop this.

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.