Home Malware Programs Malware UnityMiner Malware

UnityMiner Malware

Posted: March 10, 2021

The UnityMiner Malware is a new project that has been seeking out and infecting NAS devices made by QNAP actively. Over the past year, QNAP's products have been targeted by a wide range of malware that often relied on brute force attacks to gain access to a vulnerable system. The UnityMiner Malware, on the other hand, relies on old and known vulnerabilities in QNAP's NAS devices – CVE-2020-2506 and CVE-20-20-2507. Users who have updated their software and firmware are protected from these exploits and are unlikely to fall victim to the UnityMiner Malware.

According to reports submitted online, hundreds of thousands of devices are running outdated software currently and are vulnerable to the exploits that the UnityMiner Malware abuses. Just like other cryptocurrency mining malware, this one also focuses on mining for Monero (XMR) by using a modified open-source copy of the XMRig miner.

Once installed, the UnityMiner Malware will constantly modify the tools being used on the system. Suppose it detects that some sort of hardware monitoring tool is being used. In that case, it will display bogus statistics for the miner's CPU usage – this way, users might be unable to identify the process draining their hardware resources. The UnityMiner Malware is only compatible with AMD64 and ARM64 processors. It uses an interesting trick to keep its presence under the radar – it only utilizes half of the available CPU cores to avoid overloading the system and raising red flags.

Owners of QNAP NAS devices should strengthen their security, update the software, and rely on 3rd-party security products to secure their systems.

Loading...