{"id":24128,"date":"2019-01-03T15:12:05","date_gmt":"2019-01-03T15:12:05","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/29676\/Revamped-Cryptominer-Strikes-Asia-Through-EternalBlue-Exploit.html"},"modified":"2019-01-03T15:12:05","modified_gmt":"2019-01-03T15:12:05","slug":"revamped-cryptominer-strikes-asia-through-eternalblue-exploit","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit\/","title":{"rendered":"Revamped Cryptominer Strikes Asia Through EternalBlue Exploit"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/zdnet4.cbsistatic.com\/hub\/i\/r\/2018\/12\/11\/52b22f1f-bf38-45e5-80c6-a382ed9aed96\/thumbnail\/770x578\/5275511ca6489b26fc203cf7efe773e9\/istock-hacker-hands-doing-the-cyber-crimes-and-hacking.jpg\" class=\"ff-og-image-inserted\"\/><\/div>\n<p>The latest version of NRSMiner has been spotted in recent attacks across Asia which are compromising systems which have not been patched against the well-known EternalBlue exploit.<\/p>\n<p>According to cybersecurity researchers from F-Secure, unpatched machines in Asia &#8212; centered in Vietnam &#8212; are being infected with the latest version of NRSMiner, malware designed to steal computing resources in order to mine for cryptocurrency.<\/p>\n<div class=\"relatedContent alignRight\">\n<h3 class=\"heading\"><span class=\"int\">More security news<\/span><\/h3>\n<\/div>\n<p>Starting mid-November last year, the <a href=\"https:\/\/labsblog.f-secure.com\/2019\/01\/03\/nrsminer-updates-to-newer-version\/\" target=\"_blank\" rel=\"noopener noreferrer\">latest wave of attacks<\/a> is also actively spreading across countries including China, Japan, and Ecuador. \u00a0<\/p>\n<p>The new version of the malware relies on the EternalBlue exploit to spread through local networks.<\/p>\n<p><strong>See also:\u00a0<a href=\"https:\/\/www.zdnet.com\/article\/chinese-government-taps-into-eu-diplomatic-communications-network\/\">Chinese hackers tap into EU diplomatic communications network<\/a><\/strong><\/p>\n<p>EternalBlue is an SMBv1 (Server Message Block 1.0) exploit which is able to trigger remote code execution (RCE) attacks via vulnerable Windows Server Message Block (SMB) file-sharing services. The security flaw responsible for the attack, <a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=cve-2017-0144\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2017-0144<\/a>, was patched by Microsoft in March 2017 and yet many systems have still not been updated and remain vulnerable to attack.<\/p>\n<p>It was over a year ago that EternalBlue first hit the headlines as the world was gripped by the spread of\u00a0<a href=\"https:\/\/www.zdnet.com\/article\/wannacry-ransomware-crisis-one-year-on-are-we-ready-for-the-next-global-cyber-attack\">WannaCry<\/a>, a form of ransomware which struck organizations worldwide including the UK&#8217;s National Health Service (NHS), FedEx, Renault, and global banks. WannaCry, linked to <a href=\"https:\/\/www.zdnet.com\/article\/how-us-authorities-tracked-down-the-north-korean-hacker-behind-wannacry\/\" target=\"_blank\">North Korean hackers<\/a> and the Lazarus group, used EternalBlue as an infection vector in order to spread.<\/p>\n<section class=\"sharethrough-top\" data-component=\"medusaContentRecommendation\" data-medusa-content-recommendation-options=\"{&quot;promo&quot;:&quot;promo_ZD_recommendation_sharethrough_top_in_article_desktop&quot;,&quot;spot&quot;:&quot;dfp-in-article&quot;}\">\n<\/section>\n<p>Following the compromise of hundreds of thousands of PCs during the WannaCry outbreak, attackers then leveraged the same flaw to spread another <a href=\"https:\/\/www.zdnet.com\/article\/petya-ransomware-cyber-attack-costs-could-hit-300m-for-shipping-giant-maersk\/\">form of ransomware<\/a> known as Petya.<\/p>\n<p>It is believed EternalBlue was originally the work of the US National Security Agency (NSA)&#8217;s Equation Group, after the examination of the tool was made possible by its public release as part of a cache published online by the <a href=\"https:\/\/www.zdnet.com\/article\/cryptojacking-attack-uses-leaked-nsa-exploit\/\" target=\"_blank\">Shadow Brokers<\/a> hacking group.<\/p>\n<p><strong>Read on:<\/strong> <a href=\"https:\/\/www.zdnet.com\/article\/why-the-fixed-windows-eternalblue-exploit-wont-die\/\"><strong>Why the &#8216;fixed&#8217; Windows EternalBlue exploit won&#8217;t die<\/strong><\/a><\/p>\n<p>NRSMiner makes use of the XMRig Monero miner to hijack an infected system&#8217;s CPU to mine for the Monero (XMR) cryptocurrency. NRSMiner is also able to download update modules, refresh older versions of the malware present on a machine, and delete files and services installed by previous installs.<\/p>\n<p>The latest variant of NRSMiner infects new machines either through old versions of the same malware by forcing a download of an updater module into system&#8217;s \/temp folder or by relying on EternalBlue.<\/p>\n<p>The exploit is spread through Wininit.exe, which upon execution will decompress files including one named svchost.exe, otherwise known as EternalBlue 2.2.0. Wininit.exe will then scan TCP port 445 for any other available &#8212; and potentially vulnerable &#8212; systems before executing the exploit.<\/p>\n<p><strong>TechRepublic:\u00a0<a href=\"https:\/\/www.techrepublic.com\/article\/website-cybersecurity-paradox-whats-a-small-business-to-do\/\" target=\"_blank\" rel=\"noopener noreferrer\">Website security paradox: What&#8217;s a small business to do?<\/a><\/strong><\/p>\n<p>If successful, the DoublePulsar backdoor is then executed via a file called spoolsv.exe. DoublePulsar, a kernel payload, hooks x86 and 64-bit systems and makes use of ports to open up infected machines to additional malware payloads, as well as forge a path to a command-and-control (C&amp;C) server for the purposes of information theft and the execution of commands by C&amp;C operators.<\/p>\n<p>This backdoor is used in this scenario to both maintain persistence on an infected machine and to implement the Snmpstorsrv service, which is able to continually scan for new, vulnerable systems.<\/p>\n<p><strong>CNET:\u00a0<a href=\"https:\/\/www.cnet.com\/news\/malware-suspected-of-hobbling-newspapers-production\/\" target=\"_blank\" rel=\"noopener noreferrer\">Malware suspected of hobbling several newspapers&#8217; production<\/a><\/strong><\/p>\n<p>This is not the only case of EternalBlue being used for the purpose of cryptojacking. Other campaigns <a href=\"https:\/\/www.cybereason.com\/blog\/wannamine-cryptominer-eternalblue-wannacry\" target=\"_blank\" rel=\"noopener noreferrer\">include Wannamine<\/a>, a cut-and-paste coding effort which has still been able to compromise machines worldwide, and <a href=\"https:\/\/www.zdnet.com\/article\/cryptojacking-attack-uses-leaked-nsa-exploit\/\" target=\"_blank\">RedisWannaMine<\/a>, which targets Windows servers.<\/p>\n<p>Indicators of compromise have been listed <a href=\"https:\/\/labsblog.f-secure.com\/2019\/01\/03\/nrsminer-updates-to-newer-version\/\" target=\"_blank\" rel=\"noopener noreferrer\">by F-Secure<\/a>.<\/p>\n<h3>Previous and related coverage<\/h3>\n<p>READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/29676\/Revamped-Cryptominer-Strikes-Asia-Through-EternalBlue-Exploit.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":24129,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[60],"tags":[5408],"class_list":["post-24128","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-packet-storm","tag-headlinemalwarechinacybercrimefraudnsacryptography"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Revamped Cryptominer Strikes Asia Through EternalBlue Exploit 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Revamped Cryptominer Strikes Asia Through EternalBlue Exploit 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2019-01-03T15:12:05+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/01\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"770\" \/>\n\t<meta property=\"og:image:height\" content=\"578\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Revamped Cryptominer Strikes Asia Through EternalBlue Exploit\",\"datePublished\":\"2019-01-03T15:12:05+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit\\\/\"},\"wordCount\":616,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/01\\\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit.jpg\",\"keywords\":[\"headline,malware,china,cybercrime,fraud,nsa,cryptography\"],\"articleSection\":[\"Packet Storm\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit\\\/\",\"name\":\"Revamped Cryptominer Strikes Asia Through EternalBlue Exploit 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/01\\\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit.jpg\",\"datePublished\":\"2019-01-03T15:12:05+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/01\\\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/01\\\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit.jpg\",\"width\":770,\"height\":578},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,malware,china,cybercrime,fraud,nsa,cryptography\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinemalwarechinacybercrimefraudnsacryptography\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Revamped Cryptominer Strikes Asia Through EternalBlue Exploit\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Revamped Cryptominer Strikes Asia Through EternalBlue Exploit 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit\/","og_locale":"en_US","og_type":"article","og_title":"Revamped Cryptominer Strikes Asia Through EternalBlue Exploit 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2019-01-03T15:12:05+00:00","og_image":[{"width":770,"height":578,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/01\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Revamped Cryptominer Strikes Asia Through EternalBlue Exploit","datePublished":"2019-01-03T15:12:05+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit\/"},"wordCount":616,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/01\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit.jpg","keywords":["headline,malware,china,cybercrime,fraud,nsa,cryptography"],"articleSection":["Packet Storm"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit\/","url":"https:\/\/www.threatshub.org\/blog\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit\/","name":"Revamped Cryptominer Strikes Asia Through EternalBlue Exploit 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/01\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit.jpg","datePublished":"2019-01-03T15:12:05+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/01\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/01\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit.jpg","width":770,"height":578},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/revamped-cryptominer-strikes-asia-through-eternalblue-exploit\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,malware,china,cybercrime,fraud,nsa,cryptography","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinemalwarechinacybercrimefraudnsacryptography\/"},{"@type":"ListItem","position":3,"name":"Revamped Cryptominer Strikes Asia Through EternalBlue Exploit"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/24128","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=24128"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/24128\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/24129"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=24128"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=24128"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=24128"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}