Connect with us

Market

An AWS Virtual Machine Is Infected With Mining Malware. There Could Be Others

Published

on


A cybersecurity firm has unearthed a monero mining script embedded in a public instance of an Amazon Web Service (AWS) virtual machine. Now the firm is raising the question: How many other community Amazon Machine Instances (AMIs) are infected with the same malware?

Researchers at Mitiga revealed in a blog post Friday an AWS AMI for a Windows 2008 virtual server hosted by an unverified vendor is infected with a Monero mining script. The malware would have infected any device running the AMI with the purpose of using the device’s processing power to mine the privacy coin monero in the background – a malware attack that has become all too common in crypto’s digital wild west.

“Mitiga’s security research team has identified an AWS Community AMI containing malicious code running an unidentified crypto (Monero) miner. We have concerns this may be a phenomenon, rather than an isolated occurrence,” the blog post reads.

Monero meets AMI

Businesses and other entities use Amazon Web Services to spin up what are called “EC2” instances of popular programs and services. Also known as virtual machines, these EC2s are developed by third parties and are deployed under the Amazon Machine Instance framework, and businesses leverage these services to lower the costs of compute power for their business operations. AWS users can source these services from Amazon Marketplace AMIs, which are Amazon-verified vendors, or Community AMIs, which are unverified. 

Read more: BlackBerry and Intel Tackle Cryptojacking Malware With New Detection Tool

Mitiga discovered this monero script in a Community AMI for a Windows 2008 Server while conducting a security audit for a financial services company. In its analysis, Mititga concluded that the AMI was created with the sole purpose of infecting devices with the mining malware, as the script was included in the AMI’s code from day one.

Code for the monero mining script
Source: Mitiga

Outside of the financial services company that hired Mitiga to review the AMI, the cybersecurity firm is unaware of how many other entities and devices may be infected with the malware. 

“As to how Amazon allows this to happen, well, this is the biggest question that arises from this discovery, but it’s a question that should also be directed to AWS’s (sic) Comms team,” the team told CoinDesk over email.

CoinDesk reached out to Amazon Web Services to learn more about its approach to handling unverified AMI publishers but a representative declined to comment. Amazon Web Service’s documentation includes the caveat that users choose to use Community AMIs “at [their] own risk” and that Amazon “can’t vouch for the integrity or security of [these] AMIs.”

mitiga-community-ami-2
The AWS page containing the Community AMI that is infected with the malware
Source: Mitiga

One-off event or one of many?

Mitiga’s principal concern is that this malware could be one of several bugs worming around in unverified AMIs. The fact that Amazon does not provide transparent data regarding AWS use exacerbates this worry, the firm told CoinDesk.

“As AWS customer usage is obfuscated, we can’t know how far and wide this phenomenon stretches without AWS’s own investigation. We do however believe that the potential risk is high enough to issue a security advisory to all AWS customers using Community AMIs.”

Read more: North Korea Is Expanding Its Monero Mining Operations, Says Report 

Mitiga recommends that any entity running a community AMI should terminate it immediately and search for a replacement from a trusted vendor. At the very least, businesses that rely on AWS should painstakingly review the code before integrating unverified AMIs into their business logic. 

Mining malware could actually be the most innocuous form of infection a business may experience, the firm continued in the post. The worst-case scenario includes an AMI installing a backdoor on a business’ computer or ransomware that would encrypt the company’s files with the aim of extorting it for money to regain access.

The attack is the latest in a trend of so-called “crypto-jacking” attacks. Monero is the coin of choice among attackers thanks to its mining algorithm, which can be run easily using a computer’s CPU and GPU. When attackers infect enough computers and pool their resources, the collective hashpower is enough to merit a pretty payday.

If Mitiga’s fears are true, other AMIs may have infected user devices with monero mining scripts and gone unnoticed.

Disclosure

The leader in blockchain news, CoinDesk is a media outlet that strives for the highest journalistic standards and abides by a strict set of editorial policies. CoinDesk is an independent operating subsidiary of Digital Currency Group, which invests in cryptocurrencies and blockchain startups.



Source link

Market

MicroStrategy Buys Additional 13,005 Bitcoin for $489 Million

Published

on

By


With the current BTC price, MicroStrategy’s total Bitcoin holding is worth more than $3.4 billion.

MicroStrategy Inc (NASDAQ: MSTR) has continued its Bitcoin acquisition spree as it has purchased another $489 million worth of BTC. As of the 21st of June, the Nasdaq-listed business intelligence company holds 105,085 Bitcoins.

The company announced its latest Bitcoin acquisition earlier today. According to the company, the newly acquired BTC totaled 13,005 at an average price of about $37,617, fees and expenses included. The purchase came after MicroStrategy generated $500 million in cash from the sale of debt to fund the purchase of BTC.

Before MicroStrategy purchased the most recent Bitcoin, the company had unveiled plans to buy Bitcoin in a filing with the US Securities and Exchange Commission (SEC). In the filing, MicroStrategy said it would be selling up to 1 billion of its class A common stock through an “Open Market Sale Agreement” with Jefferies LLC. The company added that proceeds from the stock sales would be used to buy more Bitcoin. MicroStrategy explained:

We intend to use the net proceeds from the sale of any Class A common stock offered under the prospectus for general corporate purposes, including the acquisition of bitcoin, unless otherwise indicated in the applicable prospectus supplement.

MicroStrategy Focuses on Bitcoin Acquisition

In addition, MicroStrategy has made Bitcoin acquisition a focus for the company. The company said that it mainly pursues two corporate strategies. Apart from growing its enterprise analytics software business, a major strategy for the company is to acquire and hold BTC.

In the SEC filing, the Nasdaq-listed company added that it is currently seeking opportunities to implement Bitcoin-related technologies like blockchain analytics into its software offerings. Also, the company intends to hold its Bitcoin holdings long-term and not engage in regular trading.

MicroStrategy became the first publicly-traded company to buy Bitcoin in August 2020. At the time, the company bought 21,454 BTC worth $250 million, making BTC its primary treasury reserve asset. When MicroStrategy made its initial Bitcoin purchase, BTC was trading at $11,653 per coin. This means that the price of Bitcoin has surged about 5 times since the first purchase.

After debuting into the crypto space in August last year, MicroStrategy had purchased more and held more than 90,000 BTCs before its latest acquisition, announced on the 21st of June.

At the time of writing, Bitcoin is hovering around $33,000. With the current BTC price, MicroStrategy’s total Bitcoin holding is worth more than $3.4 billion. According to MicroStrategy, its new subsidiary – MacroStrategy, manages about 92,079 BTC of its coins.

MSTR stock is currently at $595.79, a 7.64% decline over its previous close of $646.46. The company has grown nearly 403% in the last twelve months and 53.57% in its year-to-date record. In addition, MicroStrategy stock has gained more than 26% over the past month. However, MSTR has shed 17.65% over the past three months and has dropped 0.30% in the last five days.

next Bitcoin News, Business News, Cryptocurrency news, Market News, News

Ibukun is a crypto/finance writer interested in passing relevant information, using non-complex words to reach all kinds of audience. Apart from writing, she likes to see movies, cook, and explore restaurants in the city of Lagos, where she resides.



Source link

Continue Reading

Market

Wise Fintech to Go Public via Direct Listing on London Stock Exchange

Published

on

By


In the future, Wise plans to roll out OwnWise, a client shareholder program that will allow its users to own a stake in the company.

British fintech Wise, formerly TransferWise, announced Thursday its plans to go public via a direct listing on the London Stock Exchange (LSE). The money transfer company said it had sufficient funding and therefore, did not require underwriters or issuing of new shares.

Wise will pioneer direct listing in London, a deal which will be finalized on July 5. Sources speculate the listing could value Wise at anywhere between $6-7 billion, up from its latest $5 billion valuations. This would also make it one of the biggest floats this year.

Founded in 2010, Wise has managed to accumulate 10 million customers who use its services to send £5 billion ($7 billion) every month. Its rivals include Western Union and MoneyGram in addition to startups like WorldRemit and Revolut.

Since 2017, Wise’s track record shows consistent profitability with a 54% annual growth rate. The latest 2021 fiscal year report shows it made £30.9 million in profits out of the £421 million ($589 million) sales revenue. This year, the company’s payments app registered £54.4 billion of international transfers for 6 million clients.

Wise Listing on LSE

Listing the giant company is a great accomplishment for London as it competes with “The Big Board”, New York Stock Exchange Group (NYSE), to attract more high growth and Blue-chip firms. As of 2020, the NYSE had 2800 company stocks and its market cap as of June, 2021 was $24.68 trillion. LSE, on the other hand, has listed over 1300 companies and its market cap is at 40.08 from today’s MarketWatch data.

To further this development, the British government is considering increasing leniency in firm enlisting guidelines to encourage issuing of dual-class shares. However, European stock markets have been hit with a lot of volatility this year, with at least two IPO cancellations in recent weeks.

The dual share structure is what Wise is opting for as it allows them to retain voting control while accommodating investors and customers into their shareholder base. At present, however, it locks them out of the lucrative Financial Times Stock Exchange (FTSE) indices.

Nevertheless, the company intends to issue both class A and class B shares with the latter holding the privilege of 9 votes per share. The expiry for Class B shares is in the fifth year following Wise’s IPO. It is likely for concerns to arise over this structure as it may give executives excessive influence on shareholder votes.

In the future, Wise plans to roll out OwnWise, a client shareholder program that will allow its users to own a stake in the company. Financial endeavors for the company are advised by Goldman Sachs, Morgan Stanley, Barclays and Citigroup.

next Business News, Market News, News, Stocks

A financial analyst who sees positive income in both directions of the market (bulls & bears). Bitcoin is my crypto safe haven, free from government conspiracies.
Mythology is my mystery!
“You cannot enslave a mind that knows itself. That values itself. That understands itself.”



Source link

Continue Reading

Market

JPMorgan Acquires Nutmeg Robo-Advisor, Furthering UK Retail Banking

Published

on

By


Before the deal, JPMorgan and Nutmeg had partnered late last year to offer clients an assortment of globally diversified exchange-traded funds (ETFs).

JPMorgan Chase & Co (NYSE: JPM) said Thursday it has closed a deal to purchase Nutmeg, an online investment management service, for an unnamed price. US biggest bank hopes the agreement, which awaits regulatory approval, will complement its launch of a standalone digital bank brand in the UK during the year.

Using the latest technology from Nutmeg will help boost JPMorgan’s retail and institutional push since the company aims at establishing as many branches as it can outside the US.

With over £3.5 billion (4.9 billion) worth of assets under management, the decade-old Nutmeg is one of the UK leading and award-winning robo-advisors. The company offers various investment accounts including Individual Savings Accounts (ISAs), general investment, and pensions accounts.

Additionally, its competitors include Wealthsimple, Moneybox, and Moneyfarm. Before the take-over, Nutmeg had raised over $150 million in investments from Goldman Sachs and the British venture capital firm – Balderton Capital.

JPMorgan CEO Jamie Dimon stated last year that the banking giant would be “much more aggressive” in adding assets by conducting more acquisitions. The bank may also be stepping up to competition from adversary Morgan Stanley (NYSE: MS) which, in recent years, has spent $20 billion in merger agreements with E-trade and Eaton Vance.

Dimon also mentioned leveling up against blue-chip tech firm Alphabet Inc (NASDAQ: GOOGL) and other fintech firms such as PayPal Holdings Inc (NASDAQ: PYPL).

JPMorgan Stock Market and Nutmeg Acquisition

Before the deal, JPMorgan and Nutmeg had partnered late last year to offer clients an assortment of globally diversified exchange-traded funds (ETFs). This is not the first time the bank has partnered with a company then acquired it later. In October 2020, JPMorgan partnered with 55ip, a tax-smart fintech start-up, then bought it a couple of months down the line.

Differing regulatory guidelines in Europe and the UK made it necessary for JPMorgan to purchase the robo-advisor, rather than use investment technology available in the US. However, its US-based investment service You Invest is currently doing well, with assets valued at about $50 billion, as Dimon states.

JPMorgan’s tech initiative marks one among many happening in Britain’s retail banking sector. Banks such as Revolut, Starling, and Monzo manage digital-only checking accounts which have attracted a host of clients. Going by data from Innovate Finance, FinTechs in the UK probably make up the world’s largest markets, having pulled in $4.1 billion investment from venture capitalists as of last year.

JPMorgan Securities served as financial advisor in the JPMorgan-Nutmeg transaction, while Freshfields Bruckhaus Deringer acted as legal counsel. Arma Partners was Nutmeg’s financial advisor and Taylor Wessing was legal counsel.

As of June 17, 2021, at 7:59 p.m. EDT, JPMorgan stock closed at $151.76, down 2.89%. In the after-hours session, it was trading at $151.48, down 0.18% in 24-hours.

next Business News, Deals News, FinTech News, Market News, News

A financial analyst who sees positive income in both directions of the market (bulls & bears). Bitcoin is my crypto safe haven, free from government conspiracies.
Mythology is my mystery!
“You cannot enslave a mind that knows itself. That values itself. That understands itself.”



Source link

Continue Reading
Advertisement

Trending