论文标题
危险组合:无归档的恶意软件和加密夹
The Dangerous Combo: Fileless Malware and Cryptojacking
论文作者
论文摘要
随着2017年新的令人震惊的威胁,无档案的恶意软件和加密劫持攻击已独立出现。2020年后,对于具有低观察特征的受害者组织,无归档攻击造成了毁灭性的毁灭性。同样,未经授权的加密货币开采数量增加了2019年。对手已经开始合并这两个不同的网络攻击,以获得“无归档的加密劫持”下的更多隐形性和利润。本文旨在在学术论文和行业报告中提供有关这种新威胁的文献综述。此外,我们提出了一种新的面向狩猎威胁的DFIR方法,其最佳实践和文献的最佳实践。最后,本文回顾了无归档威胁的基本原理,这些威胁也可以帮助勒索软件研究人员研究类似的模式。
Fileless malware and cryptojacking attacks have appeared independently as the new alarming threats in 2017. After 2020, fileless attacks have been devastating for victim organizations with low-observable characteristics. Also, the amount of unauthorized cryptocurrency mining has increased after 2019. Adversaries have started to merge these two different cyberattacks to gain more invisibility and profit under "Fileless Cryptojacking." This paper aims to provide a literature review in academic papers and industry reports for this new threat. Additionally, we present a new threat hunting-oriented DFIR approach with the best practices derived from field experience as well as the literature. Last, this paper reviews the fundamentals of the fileless threat that can also help ransomware researchers examine similar patterns.