Feeds

Crooks make it rain by seeding cloud with zombies

Your compute resources rented out

High performance access to file storage

Malware operators are once again trying to generate profits from the cloud, this time by stealing the resources of infected computers and selling them to a new distributed-computing network, researchers from Kaspersky said.

After infecting a computer, the malware downloads and installs the MetaTrader 5 Tester Agent, software that uses spare CPU cycles to test custom-written software used in financial trading systems. Operator MetaQuotes Software Corp. has more details about how to participate in its MQL5 Cloud Network here. Trojan-Downloader.Win32.MQL5Miner.a, as Kaspersky has christened the malware, sets up an account controlled by the attackers that gets credited.

With hundreds of millions of computers sitting idle on desktops around the world, there's an untold number of petaflops worth of resources that go unused each day. Legitimate software developers, such as those behind the SETI Project, have been tapping these spare CPU cycles for years. Botnet operators do much the same thing when they use infected computers to send spam or wage denial-of-service attacks.

Over the past few months, crooks have expanded the revenue potential of infected machines by using their spare resources to perform legitimate tasks. A variety of titles, including Infostealer.Coinbit,, use a hijacked PC's GPU and other resources to mine the digital currency known as Bitcoin.

“When it comes to making money, cybercriminals don't miss a trick,” Kaspersky Lab Expert Vyacheslav Zakorzhevsky wrote. “That includes exploiting the resources of infected computers without their owners' knowledge or consent.”

The malware appears to spread through email attachments. ®

High performance access to file storage

More from The Register

next story
OpenSSL Heartbleed: Bloody nose for open-source bleeding hearts
Bloke behind the cockup says not enough people are helping crucial crypto project
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
Experian subsidiary faces MEGA-PROBE for 'selling consumer data to fraudster'
US attorneys general roll up sleeves, snap on gloves
Bad PUPPY: Undead Windows XP deposits fresh scamware on lawn
Installing random interwebs shiz will bork your zombie box
prev story

Whitepapers

Mainstay ROI - Does application security pay?
In this whitepaper learn how you and your enterprise might benefit from better software security.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.