{"id":418711,"date":"2021-01-21T09:03:20","date_gmt":"2021-01-21T14:03:20","guid":{"rendered":"http:\/\/www.marketnewsdesk.com\/?p=418711"},"modified":"2021-01-21T09:03:20","modified_gmt":"2021-01-21T14:03:20","slug":"sophos-identifies-source-of-mrbminer-attacks-targeting-database-servers","status":"publish","type":"post","link":"https:\/\/www.marketnewsdesk.com\/index.php\/sophos-identifies-source-of-mrbminer-attacks-targeting-database-servers\/","title":{"rendered":"Sophos Identifies Source Of \u201cMrbMiner\u201d Attacks Targeting Database Servers"},"content":{"rendered":"<div class=\"mw_release\">\n<p align=\"left\">OXFORD, United Kingdom, Jan.  21, 2021  (GLOBE NEWSWIRE) &#8212; <a href=\"https:\/\/www.globenewswire.com\/Tracker?data=BLDyzg5Pc276DwSZC6VmTuK1z1uQfmTZn_h5DMo6MrbguwTgur4abM5-4enCjMKZsYvhOqnkBSyFI4WEU7bhXw==\" rel=\"nofollow noopener noreferrer\" target=\"_blank\"><u>Sophos<\/u><\/a>, a global leader in next-generation cybersecurity, today published a new report on MrbMiner, \u201c<a href=\"https:\/\/www.globenewswire.com\/Tracker?data=UaelKuhUkXwEYSGOKjwdsC7zxib73VDWExxlnt3FHJ0xU4VplboApY8QMP5uBYStfJJWDz5hGzrsK22MOBYgvepeap2fbNKBnn5P8oijVriFZGGkBbCjkYzlBLJu2KXmr28jJlRcD0tjrF8yQ6uQkdUm49SWXAeFyWc5AGsJTN509DwPuMutn9fsRUUlNB6ppiEDGXVyTU-8ycS40Ut8TfzfIZpelgoVqsLaMM8QjBSf_plUDMqBDrhBZJllymd1\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">MrbMiner: Cryptojacking to bypass international sanctions<\/a>,\u201d tracking its origin and management to a small software development company based in Iran.<\/p>\n<p>MrbMiner is a recently discovered cryptominer that targets internet-facing database servers (SQL servers) and downloads and installs a cryptominer. Database servers are an attractive target for cryptojackers because they are used for resource intensive activity and therefore have powerful processing capability.<\/p>\n<p>SophosLabs found that the attackers used multiple routes to install the malicious mining software on a targeted server, with the cryptominer payload and configuration files packed into deliberately mis-named zip archive files.<\/p>\n<p>The name of an Iran-based software company was hardcoded into the miner\u2019s main configuration file. This domain is connected to many other zip files also containing copies of the miner. These zip files have in turn been downloaded from other domains, one of which is mrbftp.xyz.<\/p>\n<p>\u201cIn many ways, MrbMiner\u2019s operations appear typical of most cryptominer attacks we&#8217;ve seen targeting internet-facing servers,\u201d said Gabor Szappanos, threat research director, SophosLabs. \u201cThe difference here is that the attacker appears to have thrown caution to the wind when it comes to concealing their identity. Many of the records relating to the miner&#8217;s configuration, its domains and IP addresses, signpost to a single point of origin: a small software company based in Iran.<\/p>\n<p>\u201cIn an age of multi-million dollar ransomware attacks that bring organizations to their knees it can be easy to discount cryptojacking as a nuisance rather than a serious threat, but that would be a mistake. Cryptojacking is a silent and invisible threat that is easy to implement and very difficult to detect. Further, once a system has been compromised it presents an open door for other threats, such as ransomware. It is therefore important to stop cryptojacking in its tracks. Look out for signs such as a reduction in computer speed and performance, increased electricity use, devices overheating and increased demands on the CPU.\u201d<\/p>\n<p>Further information on MrbMiner and other cyberthreats can be found on <a href=\"https:\/\/www.globenewswire.com\/Tracker?data=BLDyzg5Pc276DwSZC6VmTs8YSGnGpZPDYAt_b_3FV8LjrklurgGsNHkJYG0HJ65mJXgHB_75E4oFAGfI3G-mGeHf1mhGcMmAX77_bTdXI9ruPBud31qUkwsoGHwDn1g_StGBk0Q670cwTfRdlohwQg==\" rel=\"nofollow noopener noreferrer\" target=\"_blank\"><u>SophosLabs Uncut<\/u><\/a>, where\u00a0Sophos researchers regularly publish their latest research and breakthrough findings, such as <a href=\"https:\/\/www.globenewswire.com\/Tracker?data=SZNuT5RgHZPQnhHDihiLk3lGj5aGVIH1HqK8phVlbO8RVaV0p0LeDjVgvF3MBuvakwPz2GkVh5Jo0PoIqq7quum9n7AWrU2tNCNcJUpmNzOP9oQZC-32b1WB2R7u8CuV2fXP-vtCSTjaiu7PlyzwuUC6_QfDybKlBwL945J7_yX-Xz4wNacOS1Y_NOHCNhWe\" rel=\"nofollow noopener noreferrer\" target=\"_blank\"><u>Kingminer escalates attack complexity for cryptomining<\/u><\/a>, as well as <a href=\"https:\/\/www.globenewswire.com\/Tracker?data=rOybnd_fOcPPCNC3uLKKQVo3oOAf46DWHqoDi9D5P184M5qM_XpPjtApjuR762d_Z5LXBifuA9P8aWQ0jMGxHEgvixlMS32m-4II5GmzuudLs2Qnh7c29ShTLX2shYeMUR4E4iTWCS5pHpneekFP4oW01qdvtktA-HLDcHFN3uaH3l4aOFfKlKXQDM571ftab67clieXvjhqZvXGsLYND-jGZo61TgV8V91l1dKG4W0=\" rel=\"nofollow noopener noreferrer\" target=\"_blank\"><u>Lemon_Duck cryptominer targets cloud apps and Linux<\/u><\/a>, and <a href=\"https:\/\/www.globenewswire.com\/Tracker?data=oiVtdYMudkWuub2AqfTxAzp5RhtjpJ0q4IU2L4pii8aXiATtDUdEZ20oWH_VXfUMZssmXVSh6eHzxYha08uH9j_L3mzDaSyTb6QhwMB5qG9CzZETKtJ3jPq6KcQ_5vYCuag_GGfeMguNgjInm9Ye_38TNxMwLWKoQPguaY7dY0qQ757NJInt-UvtxQxqIgCpP8TijoRNh3u7bOvzIU1oAlp6vhkRIIv71Swc4_XH9yXtpgu7LsmidQQz5RdEfXAuAXncKVyQddrB5NYSKN-31g==\" rel=\"nofollow noopener noreferrer\" target=\"_blank\"><u>MyKings botnet spreads headaches, cryptominers and Forshare malware<\/u><\/a>. Researchers can follow SophosLabs Uncut in real time on Twitter at <a href=\"https:\/\/www.globenewswire.com\/Tracker?data=Lz_dDRYVhgs7xfOarV9xyKtcQcXlmuaANl7wtbhLMeSLjdgb6Xpq2KOnXKPRh7W5teVcJU8-3sO3cXBUHU52_A==\" rel=\"nofollow noopener noreferrer\" target=\"_blank\"><u>@SophosLabs<\/u><\/a>.<\/p>\n<p>\n        <strong>Detection and Indicators of Compromise<\/strong><br \/>\n        <br \/>Cryptominer samples of MrbMiner are detected by Sophos under the definition Troj\/Miner-ZD.<\/p>\n<p>Additional indicators of compromise have been published to the <a href=\"https:\/\/www.globenewswire.com\/Tracker?data=BLDyzg5Pc276DwSZC6VmToqakadPi1yhvcD6CkX8ButgGx38LvZl60T6_1OEvzrAThq3yP00cbrKPx8E3v7_SO6hxLR05vCdiLx2EBWxnsc=\" rel=\"nofollow noopener noreferrer\" target=\"_blank\"><u>SophosLabs Github<\/u><\/a>.<\/p>\n<p>\n        <strong>Additional Resources<\/strong>\n      <\/p>\n<ul type=\"disc\">\n<li>Learn more about current and emerging threats facing organisations, including ransomware, in the <a href=\"http:\/\/www.sophos.com\/threatreport\" rel=\"nofollow noopener noreferrer\" target=\"_blank\"><u>Sophos 2021 Threat Report<\/u><\/a><\/li>\n<li>To help stop ransomware attacks, read the <a href=\"https:\/\/news.sophos.com\/en-us\/2020\/08\/04\/the-realities-of-ransomware-five-signs-youre-about-to-be-attacked\" rel=\"nofollow noopener noreferrer\" target=\"_blank\"><u>five early indicators an attacker is present<\/u><\/a><\/li>\n<li>Learn more about <a href=\"https:\/\/www.sophos.com\/en-us\/press-office\/press-releases\/2020\/10\/sophos-launches-rapid-response-service-to-identify-and-neutralize-active-cybersecurity-attacks.aspx\" rel=\"nofollow noopener noreferrer\" target=\"_blank\"><u>Sophos\u2019 new Rapid Response service<\/u><\/a> that disrupts attacks in real-time<\/li>\n<li>Read the latest security news and views on Sophos\u2019 award-winning news website\u00a0<a href=\"https:\/\/nakedsecurity.sophos.com\/\" rel=\"nofollow noopener noreferrer\" target=\"_blank\"><u>Naked Security<\/u><\/a>\u00a0and on\u00a0<a href=\"https:\/\/news.sophos.com\/\" rel=\"nofollow noopener noreferrer\" target=\"_blank\"><u>Sophos News<\/u><\/a><\/li>\n<li>Connect with Sophos on\u00a0<a href=\"http:\/\/twitter.com\/sophos\" rel=\"nofollow noopener noreferrer\" target=\"_blank\"><u>Twitter<\/u><\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/sophos\/\" rel=\"nofollow noopener noreferrer\" target=\"_blank\"><u>LinkedIn<\/u><\/a>,\u00a0<a href=\"https:\/\/www.facebook.com\/securitybysophos\/\" rel=\"nofollow noopener noreferrer\" target=\"_blank\"><u>Facebook<\/u><\/a>,\u00a0<a href=\"https:\/\/community.spiceworks.com\/pages\/sophos\" rel=\"nofollow noopener noreferrer\" target=\"_blank\"><u>Spiceworks<\/u><\/a>, and\u00a0<a href=\"http:\/\/www.youtube.com\/user\/sophoslabs\" rel=\"nofollow noopener noreferrer\" target=\"_blank\"><u>YouTube<\/u><\/a><\/li>\n<\/ul>\n<p>\n        <strong>About Sophos<\/strong><br \/>\n        <br \/> As a worldwide leader in next-generation cybersecurity, Sophos protects more than 400,000 organizations of all sizes in more than 150 countries from today\u2019s most advanced cyber threats. Powered by SophosLabs \u2013 a global threat intelligence and data science team \u2013 Sophos\u2019 cloud-native and AI-powered solutions secure endpoints (laptops, servers and mobile devices) and networks against evolving cyberattack techniques, including ransomware, malware, exploits, data exfiltration, active-adversary breaches, phishing, and more. Sophos Central, a cloud-native management platform, integrates Sophos\u2019 entire portfolio of next-generation products, including the Intercept X endpoint solution and the XG next-generation firewall, into a single \u201csynchronized security\u201d system accessible through a set of APIs. Sophos has been driving a transition to next-generation cybersecurity, leveraging advanced capabilities in cloud, machine learning, APIs, automation, managed threat response, and more, to deliver enterprise-grade protection to any size organization. Sophos sells its products and services exclusively through a global channel of more than 53,000 partners and managed service providers (MSPs). Sophos also makes its innovative commercial technologies available to consumers via Sophos Home. The company is headquartered in Oxford, U.K. More information is available at <a href=\"https:\/\/www.globenewswire.com\/Tracker?data=ENfWHDIr5G49cVbKroDQBTyPD8hCrJN9cLepN53mB8LeUfO7gQEQpkN9s4A_VbDG231iPPZLYtHJ7-v-YDB8yw==\" rel=\"nofollow noopener noreferrer\" target=\"_blank\"><u>www.sophos.com<\/u><\/a>.<\/p>\n<\/p>\n<p>      <img loading=\"lazy\" decoding=\"async\" class=\"__GNW8366DE3E__IMG\" src=\"https:\/\/www.globenewswire.com\/newsroom\/ti?nf=ODEzOTEzMSMzOTM4MDA2IzIwOTAwNzg=\" width=\"1\" height=\"1\" \/><br \/>\n      <br \/>\n      <img loading=\"lazy\" decoding=\"async\" class=\"__GNW8366DE3E__IMG\" src=\"https:\/\/ml.globenewswire.com\/release\/track\/e58dd906-ee8e-4ccc-a8bf-d3475eef8f71\" width=\"1\" height=\"1\" \/>\n    <\/div>\n<div class=\"mw_contactinfo\">\n<pre>Hanah Johnson, sophos@marchcomms.com<\/pre>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>OXFORD, United Kingdom, Jan. 21, 2021 (GLOBE NEWSWIRE) &#8212; Sophos, a global leader in next-generation cybersecurity, today published a new report on MrbMiner, \u201cMrbMiner: Cryptojacking to bypass international sanctions,\u201d tracking its origin and management to a small software development company based in Iran. MrbMiner is a recently discovered cryptominer that targets internet-facing database servers (SQL servers) and downloads and installs a cryptominer. Database servers are an attractive target for cryptojackers because they are used for resource intensive activity and therefore have powerful processing capability. SophosLabs found that the attackers used multiple routes to install the malicious mining software on a targeted server, with the cryptominer payload and configuration files packed into deliberately mis-named zip archive files. The name of an &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.marketnewsdesk.com\/index.php\/sophos-identifies-source-of-mrbminer-attacks-targeting-database-servers\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Sophos Identifies Source Of \u201cMrbMiner\u201d Attacks Targeting Database Servers&#8221;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-418711","post","type-post","status-publish","format-standard","hentry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Sophos Identifies Source Of \u201cMrbMiner\u201d Attacks Targeting Database Servers - Market Newsdesk<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.marketnewsdesk.com\/index.php\/sophos-identifies-source-of-mrbminer-attacks-targeting-database-servers\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Sophos Identifies Source Of \u201cMrbMiner\u201d Attacks Targeting Database Servers - Market Newsdesk\" \/>\n<meta property=\"og:description\" content=\"OXFORD, United Kingdom, Jan. 21, 2021 (GLOBE NEWSWIRE) &#8212; Sophos, a global leader in next-generation cybersecurity, today published a new report on MrbMiner, \u201cMrbMiner: Cryptojacking to bypass international sanctions,\u201d tracking its origin and management to a small software development company based in Iran. MrbMiner is a recently discovered cryptominer that targets internet-facing database servers (SQL servers) and downloads and installs a cryptominer. Database servers are an attractive target for cryptojackers because they are used for resource intensive activity and therefore have powerful processing capability. SophosLabs found that the attackers used multiple routes to install the malicious mining software on a targeted server, with the cryptominer payload and configuration files packed into deliberately mis-named zip archive files. The name of an &hellip; Continue reading &quot;Sophos Identifies Source Of \u201cMrbMiner\u201d Attacks Targeting Database Servers&quot;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.marketnewsdesk.com\/index.php\/sophos-identifies-source-of-mrbminer-attacks-targeting-database-servers\/\" \/>\n<meta property=\"og:site_name\" content=\"Market Newsdesk\" \/>\n<meta property=\"article:published_time\" content=\"2021-01-21T14:03:20+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.globenewswire.com\/newsroom\/ti?nf=ODEzOTEzMSMzOTM4MDA2IzIwOTAwNzg=\" \/>\n<meta name=\"author\" content=\"Newsdesk\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Newsdesk\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/sophos-identifies-source-of-mrbminer-attacks-targeting-database-servers\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/sophos-identifies-source-of-mrbminer-attacks-targeting-database-servers\\\/\"},\"author\":{\"name\":\"Newsdesk\",\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/#\\\/schema\\\/person\\\/482f27a394d4fda80ecb5499e519d979\"},\"headline\":\"Sophos Identifies Source Of \u201cMrbMiner\u201d Attacks Targeting Database Servers\",\"datePublished\":\"2021-01-21T14:03:20+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/sophos-identifies-source-of-mrbminer-attacks-targeting-database-servers\\\/\"},\"wordCount\":699,\"image\":{\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/sophos-identifies-source-of-mrbminer-attacks-targeting-database-servers\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.globenewswire.com\\\/newsroom\\\/ti?nf=ODEzOTEzMSMzOTM4MDA2IzIwOTAwNzg=\",\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/sophos-identifies-source-of-mrbminer-attacks-targeting-database-servers\\\/\",\"url\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/sophos-identifies-source-of-mrbminer-attacks-targeting-database-servers\\\/\",\"name\":\"Sophos Identifies Source Of \u201cMrbMiner\u201d Attacks Targeting Database Servers - Market Newsdesk\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/sophos-identifies-source-of-mrbminer-attacks-targeting-database-servers\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/sophos-identifies-source-of-mrbminer-attacks-targeting-database-servers\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.globenewswire.com\\\/newsroom\\\/ti?nf=ODEzOTEzMSMzOTM4MDA2IzIwOTAwNzg=\",\"datePublished\":\"2021-01-21T14:03:20+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/#\\\/schema\\\/person\\\/482f27a394d4fda80ecb5499e519d979\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/sophos-identifies-source-of-mrbminer-attacks-targeting-database-servers\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/sophos-identifies-source-of-mrbminer-attacks-targeting-database-servers\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/sophos-identifies-source-of-mrbminer-attacks-targeting-database-servers\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.globenewswire.com\\\/newsroom\\\/ti?nf=ODEzOTEzMSMzOTM4MDA2IzIwOTAwNzg=\",\"contentUrl\":\"https:\\\/\\\/www.globenewswire.com\\\/newsroom\\\/ti?nf=ODEzOTEzMSMzOTM4MDA2IzIwOTAwNzg=\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/sophos-identifies-source-of-mrbminer-attacks-targeting-database-servers\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Sophos Identifies Source Of \u201cMrbMiner\u201d Attacks Targeting Database Servers\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/#website\",\"url\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/\",\"name\":\"Market Newsdesk\",\"description\":\"Latest Business News in Real Time\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/#\\\/schema\\\/person\\\/482f27a394d4fda80ecb5499e519d979\",\"name\":\"Newsdesk\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a0d0bd5b0f0ca12a265a459b13169dac35f33776d8501eda5e68844a366f2f46?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a0d0bd5b0f0ca12a265a459b13169dac35f33776d8501eda5e68844a366f2f46?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a0d0bd5b0f0ca12a265a459b13169dac35f33776d8501eda5e68844a366f2f46?s=96&d=mm&r=g\",\"caption\":\"Newsdesk\"},\"url\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/author\\\/newsdesk\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Sophos Identifies Source Of \u201cMrbMiner\u201d Attacks Targeting Database Servers - Market Newsdesk","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.marketnewsdesk.com\/index.php\/sophos-identifies-source-of-mrbminer-attacks-targeting-database-servers\/","og_locale":"en_US","og_type":"article","og_title":"Sophos Identifies Source Of \u201cMrbMiner\u201d Attacks Targeting Database Servers - Market Newsdesk","og_description":"OXFORD, United Kingdom, Jan. 21, 2021 (GLOBE NEWSWIRE) &#8212; Sophos, a global leader in next-generation cybersecurity, today published a new report on MrbMiner, \u201cMrbMiner: Cryptojacking to bypass international sanctions,\u201d tracking its origin and management to a small software development company based in Iran. MrbMiner is a recently discovered cryptominer that targets internet-facing database servers (SQL servers) and downloads and installs a cryptominer. Database servers are an attractive target for cryptojackers because they are used for resource intensive activity and therefore have powerful processing capability. SophosLabs found that the attackers used multiple routes to install the malicious mining software on a targeted server, with the cryptominer payload and configuration files packed into deliberately mis-named zip archive files. The name of an &hellip; Continue reading \"Sophos Identifies Source Of \u201cMrbMiner\u201d Attacks Targeting Database Servers\"","og_url":"https:\/\/www.marketnewsdesk.com\/index.php\/sophos-identifies-source-of-mrbminer-attacks-targeting-database-servers\/","og_site_name":"Market Newsdesk","article_published_time":"2021-01-21T14:03:20+00:00","og_image":[{"url":"https:\/\/www.globenewswire.com\/newsroom\/ti?nf=ODEzOTEzMSMzOTM4MDA2IzIwOTAwNzg=","type":"","width":"","height":""}],"author":"Newsdesk","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Newsdesk","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.marketnewsdesk.com\/index.php\/sophos-identifies-source-of-mrbminer-attacks-targeting-database-servers\/#article","isPartOf":{"@id":"https:\/\/www.marketnewsdesk.com\/index.php\/sophos-identifies-source-of-mrbminer-attacks-targeting-database-servers\/"},"author":{"name":"Newsdesk","@id":"https:\/\/www.marketnewsdesk.com\/#\/schema\/person\/482f27a394d4fda80ecb5499e519d979"},"headline":"Sophos Identifies Source Of \u201cMrbMiner\u201d Attacks Targeting Database Servers","datePublished":"2021-01-21T14:03:20+00:00","mainEntityOfPage":{"@id":"https:\/\/www.marketnewsdesk.com\/index.php\/sophos-identifies-source-of-mrbminer-attacks-targeting-database-servers\/"},"wordCount":699,"image":{"@id":"https:\/\/www.marketnewsdesk.com\/index.php\/sophos-identifies-source-of-mrbminer-attacks-targeting-database-servers\/#primaryimage"},"thumbnailUrl":"https:\/\/www.globenewswire.com\/newsroom\/ti?nf=ODEzOTEzMSMzOTM4MDA2IzIwOTAwNzg=","inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.marketnewsdesk.com\/index.php\/sophos-identifies-source-of-mrbminer-attacks-targeting-database-servers\/","url":"https:\/\/www.marketnewsdesk.com\/index.php\/sophos-identifies-source-of-mrbminer-attacks-targeting-database-servers\/","name":"Sophos Identifies Source Of \u201cMrbMiner\u201d Attacks Targeting Database Servers - Market Newsdesk","isPartOf":{"@id":"https:\/\/www.marketnewsdesk.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.marketnewsdesk.com\/index.php\/sophos-identifies-source-of-mrbminer-attacks-targeting-database-servers\/#primaryimage"},"image":{"@id":"https:\/\/www.marketnewsdesk.com\/index.php\/sophos-identifies-source-of-mrbminer-attacks-targeting-database-servers\/#primaryimage"},"thumbnailUrl":"https:\/\/www.globenewswire.com\/newsroom\/ti?nf=ODEzOTEzMSMzOTM4MDA2IzIwOTAwNzg=","datePublished":"2021-01-21T14:03:20+00:00","author":{"@id":"https:\/\/www.marketnewsdesk.com\/#\/schema\/person\/482f27a394d4fda80ecb5499e519d979"},"breadcrumb":{"@id":"https:\/\/www.marketnewsdesk.com\/index.php\/sophos-identifies-source-of-mrbminer-attacks-targeting-database-servers\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.marketnewsdesk.com\/index.php\/sophos-identifies-source-of-mrbminer-attacks-targeting-database-servers\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.marketnewsdesk.com\/index.php\/sophos-identifies-source-of-mrbminer-attacks-targeting-database-servers\/#primaryimage","url":"https:\/\/www.globenewswire.com\/newsroom\/ti?nf=ODEzOTEzMSMzOTM4MDA2IzIwOTAwNzg=","contentUrl":"https:\/\/www.globenewswire.com\/newsroom\/ti?nf=ODEzOTEzMSMzOTM4MDA2IzIwOTAwNzg="},{"@type":"BreadcrumbList","@id":"https:\/\/www.marketnewsdesk.com\/index.php\/sophos-identifies-source-of-mrbminer-attacks-targeting-database-servers\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.marketnewsdesk.com\/"},{"@type":"ListItem","position":2,"name":"Sophos Identifies Source Of \u201cMrbMiner\u201d Attacks Targeting Database Servers"}]},{"@type":"WebSite","@id":"https:\/\/www.marketnewsdesk.com\/#website","url":"https:\/\/www.marketnewsdesk.com\/","name":"Market Newsdesk","description":"Latest Business News in Real Time","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.marketnewsdesk.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.marketnewsdesk.com\/#\/schema\/person\/482f27a394d4fda80ecb5499e519d979","name":"Newsdesk","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a0d0bd5b0f0ca12a265a459b13169dac35f33776d8501eda5e68844a366f2f46?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a0d0bd5b0f0ca12a265a459b13169dac35f33776d8501eda5e68844a366f2f46?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a0d0bd5b0f0ca12a265a459b13169dac35f33776d8501eda5e68844a366f2f46?s=96&d=mm&r=g","caption":"Newsdesk"},"url":"https:\/\/www.marketnewsdesk.com\/index.php\/author\/newsdesk\/"}]}},"_links":{"self":[{"href":"https:\/\/www.marketnewsdesk.com\/index.php\/wp-json\/wp\/v2\/posts\/418711","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.marketnewsdesk.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.marketnewsdesk.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.marketnewsdesk.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.marketnewsdesk.com\/index.php\/wp-json\/wp\/v2\/comments?post=418711"}],"version-history":[{"count":0,"href":"https:\/\/www.marketnewsdesk.com\/index.php\/wp-json\/wp\/v2\/posts\/418711\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.marketnewsdesk.com\/index.php\/wp-json\/wp\/v2\/media?parent=418711"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.marketnewsdesk.com\/index.php\/wp-json\/wp\/v2\/categories?post=418711"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.marketnewsdesk.com\/index.php\/wp-json\/wp\/v2\/tags?post=418711"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}