Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Bitcoin may have bottomed at $60,000, says Coinbase (COIN) CEO

June 15, 2026

The CLARITY Act has a two-month window. Here is the map

June 15, 2026

LayerZero rallies 14% ahead of $23mln token unlock – Can ZRO break $1.15?

June 15, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Researchers Reveal Stealthy Crypto-Miner “Norman”
Researchers Reveal Stealthy Crypto-Miner “Norman”
Security and Privacy

Researchers Reveal Stealthy Crypto-Miner “Norman”

August 4, 2023No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Security researchers have found a stealthy new cryptocurrency mining malware variant which was used as part of an attack that infected almost an entire organization.

After being notified of unstable applications and network slowdowns in a client organization, security firm Varonis decided to investigate further.

“Almost every server and workstation was infected with malware. Most were generic variants of cryptominers. Some were password dumping tools, some were hidden PHP shells, and some had been present for several years,” it explained in a blog post.

“Out of all the cryptominer samples that we found, one stood out. We named it ‘Norman’.”

Norman is a high-performance miner of Monero currency that differed from many of the other samples discovered in its sophisticated attempts to stay hidden.

Unusually, it is compiled with Nullsoft Scriptable Install System (NSIS), an open source system usually employed to create Windows installers.

The injection payload is designed to execute a cryptocurrency miner and stay hidden, said Varonis.

It avoids detection by terminating the miner function when the Task Manager is opened by a curious user. Once closed, it will re-inject the miner and start again.

The miner itself is XMRig, obfuscated in the malware by UPX and injected into either Notepad or Explorer depending on the execution path.

Varonis believes the cryptocurrency mining malware it discovered could be linked to a PHP shell it found in the victim organization continually connecting to a command-and-control (C2) server. Like Norman, the PHP shell used DuckDNS for C2 comms.

“None of the malware samples had any lateral movement capabilities, though they had spread across different devices and network segments,” the firm explained. “Though the threat actor could have infected each host individually (perhaps via the same vector used in the initial infection), it would have been more efficient to use the PHP-Shell to move laterally and infect other devices in the victim’s network.”

See also  Web3 Projects Lose $2,020,000,000 in 2023 to Hacks, Rug Pulls and Phishing Attacks: Crypto Security Firm

However, it also claimed there were no coding similarities between the two, or communications capabilities between the crypto-mining malware and PHP shell.

The malware authors could be French speaking, given the language was present in some of the code.

Varonis urged firms worried about crypto-jacking to: keep operating systems up-to-date; monitor network traffic and web proxies; maintain anti-virus on endpoints; keep an eye on DNS and CPU activity; and have an incident response plan ready and tested.

Source link

Cryptominer Norman Researchers Reveal Stealthy
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

What The FIFA World Cup 2026 Means For Fraud

June 12, 2026

Kalshi now requires users to reveal employers as it fights insider trading and market manipulation

June 11, 2026

New SilabRAT Trojan Hijacks Sessions to Steal Crypto

June 10, 2026

North Korean Hackers Use Fake Coding Tasks to Steal Crypto

June 8, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

ParaSpace Support Azuki Owners To Airdrop Elementals Right On Platform

July 5, 2023

Man Sues City Council for $647,000,000 for Blocking Him From Digging Up Old Hard Drive With Bitcoin: Report

October 14, 2024

cLabs CTO Marek Olszewski on why Celo wants to ‘come home’ to Ethereum

November 16, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Bitcoin may have bottomed at $60,000, says Coinbase (COIN) CEO

June 15, 2026

The CLARITY Act has a two-month window. Here is the map

June 15, 2026

LayerZero rallies 14% ahead of $23mln token unlock – Can ZRO break $1.15?

June 15, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$66,497.004.09%
  • ethereumEthereum(ETH)$1,811.149.32%
  • tetherTether(USDT)$1.00-0.02%
  • binancecoinBNB(BNB)$626.943.46%
  • rippleXRP(XRP)$1.2410.07%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$73.7810.02%
  • tronTRON(TRX)$0.3190540.66%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.010.00%
  • HyperliquidHyperliquid(HYPE)$67.3112.41%