TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Detecting Monero Miners with Bpftrace

192 pointsby philkuzabout 3 years ago

9 comments

garaetjjteabout 3 years ago
&gt;If these cryptojackers were to mine Bitcoin or Ethereum, their transaction details would be open to the public, making it possible for law enforcement to track them down<p>That doesn&#x27;t actually matter at all. Monero is used for these purposes probably just because it&#x27;s mineable only on CPU, thus viable to mine on ordinary hardware. (Bitcoin requires ASIC and Ethereum high-end GPU)
评论 #30433089 未加载
评论 #30434377 未加载
Scoundrellerabout 3 years ago
My employer does a pretty good job of giving us terrible hardware so the thought of mining on it is self-discouraging.<p>They have no problems giving us space heaters though.<p>As largely a joke, I sometimes fire up monero mining on my laptop at home because the average proceeds exceed electricity cost, even though it’ll take me about a decade to ever get a block. The heat is just cake icing.
评论 #30438941 未加载
alfonmgaabout 3 years ago
I feel bad about this because I wrote an article[0] about how to hide Monero miners on Linux systems. Sometimes I ask myself if I should unpublish it as probably some of the criminals doing this type of attacks found it helpful.<p>[0] <a href="https:&#x2F;&#x2F;alfon.xyz&#x2F;posts&#x2F;hiding-cryptominers-linux" rel="nofollow">https:&#x2F;&#x2F;alfon.xyz&#x2F;posts&#x2F;hiding-cryptominers-linux</a>
评论 #30437464 未加载
评论 #30435701 未加载
评论 #30435928 未加载
评论 #30435973 未加载
评论 #30439301 未加载
评论 #30435455 未加载
a_bonoboabout 3 years ago
Overheard this from HPC people: &#x27;it&#x27;s easy to detect cryptominers on the system, it&#x27;s the only software that uses the nodes efficiently&#x27;
unnouinceputabout 3 years ago
Title is somehow misleading. This is not about uncovering Monero users in the wild and exposing them which are criminals, as I first believed when reading the title. This is about detecting unwanted Monero miner on your system. But if you&#x27;re already pwned that an unwanted process is already running on your system, a Monero miner is the least of your worries.
评论 #30434079 未加载
评论 #30436303 未加载
wanderer_about 3 years ago
Now they just need to do it with the chip&#x27;s EM signature like in that PoC a few weeks ago...<p><a href="https:&#x2F;&#x2F;hackaday.com&#x2F;2022&#x2F;01&#x2F;19&#x2F;identifying-malware-by-sniffing-its-em-signature&#x2F;" rel="nofollow">https:&#x2F;&#x2F;hackaday.com&#x2F;2022&#x2F;01&#x2F;19&#x2F;identifying-malware-by-sniff...</a>
badrabbitabout 3 years ago
I just use a list of mining pool domains. Works well.
m00dyabout 3 years ago
How can we detect it inside the browser ?
评论 #30433003 未加载
评论 #30433648 未加载
devops000about 3 years ago
Monero is not anonymous anymore as soon as you want to convert to fiat.
评论 #30433335 未加载
评论 #30435349 未加载
评论 #30432948 未加载