Cointime

Download App
iOS & Android

Librarian Ghouls hacker group targeting Russians to mine crypto

The Librarian Ghouls hacker group has compromised hundreds of Russian devices and used them to mine crypto in an apparent case of cryptojacking, cybersecurity firm Kaspersky says.

The hacker group, which is also known as Rare Werewolf, gains access to systems through malware-ridden phishing emails disguised as messages from legitimate organizations that appear to be official documents or payment orders, Kaspersky said in a report on Monday.

  Bad actors can gain access to devices to steal resources such as computing power and mine crypto. Source: Cointelegraph


Hackers scope out device info before mining

After a computer is infected with the malware, the hackers establish a remote connection and disable security systems such as Windows Defender.

The infected device is also programmed to turn on at 1 am and shut down at 5 am, with the hackers using the time frame to further establish unauthorized remote access and steal login credentials.

“It is our assessment that the attackers use this technique to cover their tracks so that the user remains unaware that their device has been hijacked,” Kaspersky said.

They then steal login credentials and also collect information about the device’s available RAM, CPU cores and GPUs to optimally configure the crypto miner before deploying it.

While the miner is running, the hackers maintain a connection to the mining pool, sending a request every 60 seconds, according to Kaspersky.

“We observe that the attackers are continuously refining their tactics, encompassing not only data exfiltration but also the deployment of remote access tools and the use of phishing sites for email account compromise,” the firm said.

Cryptojacking campaign ongoing since 2024

So far, the hacking campaign, which started in December and is ongoing, has affected hundreds of Russian users, particularly industrial enterprises and engineering schools, with additional victims reported in Belarus and Kazakhstan.

The origin of the group hasn’t been established; however, Kaspersky said the phishing emails are “composed in Russian and include archives with Russian filenames, along with Russian-language decoy documents.”

“This suggests that the primary targets of this campaign are likely based in Russia or speak Russian,” Kaspersky said.

Librarian Ghouls could be hacktivists

Kaspersky speculates that the Librarian Ghouls might be hacktivists, who use hacking as a form of civil disobedience to promote a political agenda, due to the use of techniques commonly associated with similar groups, such as reliance on legitimate, third-party utilities.

“A distinctive feature of this threat is that the attackers favor using legitimate third-party software over developing their own malicious binaries,” Kaspersky said.

It’s unknown how long the group has been active, but another Russian cybersecurity firm, BI. ZONE said in a Nov. 23 report that Rare Werewolf has been around since at least 2019. 

Comments

All Comments

Recommended for you

  • BTC Falls Below $77,000

    Market data shows that BTC has fallen below $77,000, currently priced at $76,997.37, with a 24-hour increase of 2.68%. The market is experiencing significant fluctuations, so please ensure proper risk management.

  • Iranian Civil Aviation Organization Announces Partial Reopening of Airspace

    According to Iranian media reports on the 18th, the Iranian Civil Aviation Organization announced the reopening of part of Iran's airspace and several airports. (Xinhua)

  • Bitcoin ETF Sees $663.9 Million Net Inflow, Ethereum ETF Sees $127.4 Million Net Inflow

    On April 18, according to Farside Investors, the U.S. Bitcoin spot ETF saw a net inflow of $663.9 million yesterday, with IBIT net inflow at $284 million, FBTC net inflow at $163.4 million, and ARKB net inflow at $117.9 million. The Ethereum ETF recorded a net inflow of $127.4 million yesterday, marking the seventh consecutive day of net inflows, with ETHA net inflow at $30.8 million and FETH net inflow at $84.1 million.

  • Trump Hints at 'Good News' on Iran Issue

    On April 18, U.S. President Donald Trump stated that there is some 'pretty good news' regarding the Iran issue, but he declined to provide further details. 'We heard some pretty good news about 20 minutes ago, and it seems that progress related to Iran in the Middle East is going very smoothly,' Trump told reporters aboard Air Force One. When asked what the so-called good news was, Trump replied, 'You will hear it. I think it is something that should happen. It is a matter of course. And I believe it will happen. We will see, but I think it will happen.' (Jinshi)

  • Trump Suggests War Will Resume if No Agreement with Iran is Reached

    On April 18, President Trump told reporters aboard Air Force One that if an agreement with Iran is not reached by Wednesday, war will resume. When asked if he was prepared to extend the ceasefire agreement if no deal is made by the time the ceasefire expires on Wednesday, Trump replied, "Maybe I won't extend the ceasefire. But the blockade will continue. So, the blockade remains in place, and unfortunately, we will have to start dropping bombs again," Trump warned.

  • Chinese Ship Trapped in Strait of Hormuz Informs Crew to Prepare for Departure

    On April 18, according to Yicai, around 4 PM local time on the 17th, the Chinese ship trapped in the Strait of Hormuz has informed its crew to 'prepare for departure.' According to CCTV, on the afternoon of the 17th, Iranian Foreign Minister Amir-Abdollahian stated on social media that, based on the ceasefire agreement in Lebanon, all commercial vessels are allowed to pass through the Strait of Hormuz completely open during the remaining time of the ceasefire, following the coordinated routes announced by Iranian ports and maritime organizations.

  • DeepSeek Seeks Over $300 Million in First Round of External Funding

    According to The Information, DeepSeek is seeking over $300 million in its first round of external funding, with a valuation exceeding $10 billion.

  • BTC Surpasses $78,000

    Market data shows that BTC has surpassed $78,000, currently priced at $78,024.64, with a 24-hour increase of 5.63%. The market is highly volatile, so please ensure proper risk management.

  • BTC Surpasses $77,000

    Market data shows that BTC has surpassed $77,000, currently priced at $77,022.24, with a 24-hour increase of 3.42%. Due to significant market fluctuations, please ensure proper risk management.

  • US and Iran Discuss Plan to End War

    On April 17, U.S. media reported, citing two American officials and two sources familiar with the negotiations, that the United States and Iran are communicating about a plan aimed at ending the war. One key topic is the U.S. potentially unfreezing $20 billion of Iran's frozen assets in exchange for Iran giving up its enriched uranium stockpile. The report also quoted another source familiar with the mediation efforts, stating that negotiations are expected to take place this Sunday in Islamabad, the capital of Pakistan. (Xinhua News Agency)