Threat Database Malware CookieMiner

CookieMiner

By GoldSparrow in Malware

CookieMiner is a digital currency miner that is used to mine Koto by taking advantage of the infected computer's resources. These malware threats will typically make the affected devices slower and unstable since they will dedicate the infected machine's resources to mine digital currency, which takes up significant memory and processing power. CookieMiner functions as a CPU Miner and is used for a Japanese cryptocurrency known as Koto mainly. CookieMiner will collect information about Web browser cookies from the affected computer's Web browser as well, targeting Google Chrome and Safari. It is important to protect your devices from threats like CookieMiner by using a strong security program if symptoms of digital currency mining malware are detected especially.

A CookieMiner Infection is a Threat to Your Privacy

CookieMiner seems to be based on DarthMiner, a known Trojan that uses backdoor components to carry out its attacks and infect the targeted devices. CookieMiner itself was first observed on January 31, 2019, although it is a variant of threats that had already been existent and active for some time before. Typically, CookieMiner is installed onto the victim's computers when the computer users download and install software from dubious sources, such as a cracked or pirated version of a popular application. Once installed, CookieMiner will carry out its attack, taking over the victim's computer with the goal of violating the victim's privacy while at the same time using the infected device's resources to mine Koto.

How CookieMiner Carries Out Its Attack

Once CookieMiner has been installed on a computer, it will carry out a variety of operations intended to violate the victims' privacy and generate revenue at the expense of the affected device. The following operations have been associated with the CookieMiner Trojan:

  1. CookieMiner will collect Web browser cookies from Safari and Google Chrome. CookieMiner seems to target cookies associated with online digital currency platforms and wallets, to attempt to collect the victim's digital currency funds possibly.
  2. CookieMiner will try to collect login information and credit card information that may have been stored on Google Chrome on the infected device.
  3. CookieMiner will attempt to collect text messages that are backed up or stored on the infected device, iPhone message particularly.
  4. CookieMiner will search for authentication keys and information related to digital currency wallets.

Using a combination of all of the data that was collected, the criminals can transfer the victim's data and funds to their own accounts. The combination of collecting text messages and similar data can be used to bypass two-factor authentication systems that may be used to protect online bank accounts and digital currency wallets. CookieMiner also will carry out attacks associated with XMRig, a CPU Miner that has been used in the part to mine a variety of digital currencies on the victims' computers, apart from the backdoor and data collecting operations outlined above. Through this component, CookieMiner can use up to 90% of the affected computer's processing power and memory to mine for digital currency. This will cause numerous symptoms on infected computers.

Symptoms of Infections Like CookieMiner

When digital currency miners like CookieMiner use up affected the computers' resources to mine for digital currency, they will cause a variety of symptoms, which may include the following:

  • Programs like CookieMiner can cause the computers to overheat frequently.
  • Mining digital currency is a memory intensive operation, which will cause the affected computers to slow down dramatically, become stuck frequently or fail to carry out basic tasks.
  • CookieMiner and similar software may interfere with legitimate software installed on the affected computer, causing the affected device to become unstable and perform erratically.
  • CookieMiner and similar threats will affect the devices' network connections, slowing them or stalling them.

Trending

Most Viewed

Loading...