New Linux Cryptojacker Can Mask CPU Usage and Fake Network Activity

Skidmap Featured

Cryptojacking is a lucrative venture for malware developers, but it comes with a problem. Cryptojackers take up a lot of the processor’s resources which makes the attack very noticeable for the victim. One strain of cryptojacker has developed a way to avoid detection by masking the tell-tale signs from the user.1

The Arrival of Skidmap

Skidmap is a Linux-based malware which mines cryptocurrency on computers and servers without the owner’s permission. What makes Skidmap so dangerous is its wide range of advanced features that make it a pain to locate and stop.

Hiding the CPU’s True Usage

Skidmap Processor

For one, it can mask its CPU usage. It does this by using a rootkit that masks how much of the processor is being used. This is handy for Skidmap, as its performance-tanking attack will cause users to look at their system resources. Should they see the spoofed CPU usage, they’ll assume any slowdowns as another part of the computer, thus taking heat off the malware.

Hiding Its Network Activity

Cryptojackers need to send data to mine the funds for their owner. This, too, can be a “fingerprint” that will give away a cryptojacker’s location. As such, it uses its rootkit to mask its network traffic so that the user can’t spot the communications going to and from the malware.

Persisting Past Cleanup

Skidmap can also infect the kernel of the operating system, meaning it’s harder to clean it out completely. Even if the user manages it, Skidmap has many ways of sneaking around a network, meaning it can re-infect cleaned devices.

Also read: How to Scan a Linux Server for Malware and Rootkit

Why Does It Infect Linux?

Skidmap Linux

Typically, malware that makes the developer money targets Windows. This is because of Windows’ high adoption rate; the more computers that run Windows, the further the malware can spread, and the more money the developer makes. So, why does this one target Linux – the OS that’s cited as the hardest option to spread malware?

Legitimate cryptominers know of the weaknesses of mainstream OSs and have shored up with Linux for their mining needs. This makes a malware attack less likely than with a Windows machine.

As a result, heavy duty mining rigs typically run Linux. These are prime targets for cryptojacker developers, who are keen to bandwagon off the rig’s processing power to make themselves some money.

What to Do in the Face of Skidmap

Skidmap Coin

Due to Skidmap’s evasive nature, it’s highly recommended not to allow it to get a foothold on your system. As such, the common practices for avoiding a nasty infection are recommended here.

Keep your servers and systems up to date to help combat this threat. Try not to download and open files on a mining computer or even on a computer on the same network. Don’t give root permission to unknown files. Your computers may be running Linux, but these days it doesn’t give you a free pass for malware!

Mapping Out Skidmap’s Plan

Skidmap is a nasty example of advanced cryptojacking. It can burrow into a Linux kernel, survive multiple wipes, and mask its footprints using false CPU usage information and fake network traffic. A Skidmap infection is hard to shake, so do your best to prevent the initial infection.

Will this news make you more wary of a cryptojacker infection? Let us know below.

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Simon Batt Avatar

Read next

When the SS Great Eastern laid the first working transatlantic telegraph cable in 1866, a message that had taken ten days by steamship suddenly crossed the ocean in minutes, and the financial markets of London and New York were forced, within a single trading week, to invent the modern concept of synchronised global price.
The Big Ear telescope was scanning at 1420.4056 megahertz on the night of 15 August 1977, the exact frequency at which hydrogen atoms vibrate across the universe, because Giuseppe Cocconi and Philip Morrison had argued years earlier that any species trying to be found would broadcast on that channel — and then, for 72 seconds, something did.
In 2016, archaeologists dated two rings of snapped stalagmites in France’s Bruniquel Cave to 176,500 years ago, evidence that Neanderthals had walked 336 metres into darkness with fire and built architecture deep underground long before modern humans reached Europe
Otto von Bismarck was 74 when Germany adopted the world’s first national old-age social insurance program in 1889, setting the pension age at 70 after years of fighting socialists with bans, laws, and a promise few workers would live long enough to use
When cosmonaut Valeri Polyakov stepped out of his Soyuz capsule in March 1995 after 437 consecutive days aboard Mir, doctors recorded him at several centimetres above his pre-flight height, and his spine had become so unaccustomed to gravity that the recovery team carried him to a chair rather than risk the compression of letting him walk.
When Bell Labs engineer Karl Jansky pointed a rotating antenna at the sky in 1932 looking for sources of transatlantic radio static, he kept picking up a faint hiss that peaked every 23 hours and 56 minutes, and he eventually realized he had become the first human to hear the center of the Milky Way.
When Harvard astronomer Cecilia Payne submitted her 1925 doctoral thesis arguing that the Sun was made almost entirely of hydrogen, the field’s senior figure Henry Norris Russell talked her into adding a line calling the result ‘almost certainly not real,’ and then published the same conclusion himself four years later to widespread acclaim.
When seismic waves from the Chicxulub impact reached what is now North Dakota roughly ten minutes after the asteroid struck, they appear to have triggered a ten-metre standing wave in an inland river that flung fish onto the bank and buried them under glass beads still falling from the sky.