Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

U.S. CFTC’s Selig says AI has helped make up for staffing cuts at key crypto watchdog

April 16, 2026

Public crypto miners sold more BTC in Q1 2026 than all of 2025: Report

April 16, 2026

SEC Approves Elimination of Pattern Day Trader Rule and $25,000 Minimum: FINRA

April 16, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»PyRo Mine Malware Uses NSA Tool to Collect Monero
PyRo Mine Malware Uses NSA Tool to Collect Monero
Security and Privacy

PyRo Mine Malware Uses NSA Tool to Collect Monero

August 28, 2023No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Attackers are known to leverage any means available to go after cryptocurrencies, and Fortinet researchers reported this week that hackers are using a new crypto-mining malware they are calling PyRo Mine to quietly collect Monero.

The Python-based malware uses an NSA exploit to spread to Windows machines while also disabling security software and allowing the exfiltration of unencrypted data. By also configuring the Windows Remote Management Service, the machine becomes vulnerable to future attacks.

“Researchers have discovered malware authors using the ETERNALBLUE exploit in cryptocurrency mining malware, such as Adylkuzz, Smominru, and WannaMine. PyRo Mine uses the ETERNALROMANCE exploit,” wrote Fortinet security researcher Jasper Manuel in his blog.

The malicious URL with a downloadable zip file compiled with PyInstaller is dangerous because it packages Python programs into stand-alone executable so that the attacker does not need to install Python on the machine to execute the program.

“Several of the latest tool sets are coming armed with various payloads that simply have functionality to deploy attacks, harvest for data and also take advantage of lax security and processing time. And, this all comes in a nice, neat package using the simple issue that we (the human) haven’t patched or don’t pay attention to when we are downloading/clicking,” said chief security architect at ACALVIO, Chris Roberts.

The combined attack techniques Manuel discovered in analyzing the scripts and packages let the malicious actor stay hidden while deploying additional attack vectors. Because they don’t make a lot of noise, they can go unnoticed for longer periods of time.

“Looking at the script, I realized that the code was copied from the ETERNALROMANCE implementation found on the exploit database website, with a few modifications to fit its need. This malware gets the local IP addresses to find the local subnet(s), then iterates through all the IPs of these subnets to execute the payload,” said Manuel.

See also  US, UK intel agencies warn against new crypto malware: Report

After the attacker successfully accesses the system, they can start mining for Monero, most likely chosen “because it is designed to mine common CPUs present in every laptop and desktop where most crypto-mining relies on expensive GPUs,” said Chris Morales, head of security analytics at Vectra.

Though not widely spread as of yet, those who have not patched these known vulnerabilities remain potential targets as experts expect to see more of these types of attacks in the future.

Source link

collect Malware Monero NSA PyRo Tool
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Cookeville Hospital Discloses Rhysida Breach Hitting 337,917

April 16, 2026

Kraken is actively being extorted by criminals threatening to release the top crypto exchange’s internal data

April 14, 2026

Operation Atlantic Seizes $12m in Crypto Losses

April 13, 2026

Integrating Monero, Bittensor, and Zcash Mainnets for Enhanced Cross-Chain Liquidity

April 13, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Crypto Already Visible at Formula One Events. Now Cue NFT Tickets.

May 29, 2023

SWIFT Reaches MVP Stage for Blockchain-Based Shared Ledger

April 1, 2026

Kraken says it fought IRS to protect clients against identity theft, other potential harms

July 3, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

U.S. CFTC’s Selig says AI has helped make up for staffing cuts at key crypto watchdog

April 16, 2026

Public crypto miners sold more BTC in Q1 2026 than all of 2025: Report

April 16, 2026

SEC Approves Elimination of Pattern Day Trader Rule and $25,000 Minimum: FINRA

April 16, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$74,976.000.30%
  • ethereumEthereum(ETH)$2,340.57-0.85%
  • tetherTether(USDT)$1.00-0.01%
  • rippleXRP(XRP)$1.454.46%
  • binancecoinBNB(BNB)$633.331.53%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$89.035.11%
  • tronTRON(TRX)$0.327071-0.22%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03-0.08%
  • dogecoinDogecoin(DOGE)$0.0985683.75%