Site icon The Ultimate Linux Newbie Guide

Your Raspberry Pi as a Zombie Bitcoin Harvesting Beast

Raspberry Pi Logo

But mommy, I just wanted to play with my Pi…

Straight from the bowels of all things unholy on the Interwebs, it now turns out that some ‘so called’ malware is infecting a plethora of Raspberry Pi linux boxes the world over.

Stupid is bash, stupid does

The ‘malware’ is really nothing more than a fishing expedition gone greedy. When you buy a new Raspberry Pi, it usually comes with Raspbian Linux on it. The default user is called ‘pi’, and guess what Einstein, the default password is ‘raspberry’. Can you guess what’s coming next?

By the sounds of it, the pimply faced bedroom based teenager that probably wrote this thing is laughing the way to the bank. The bank of Monero that is. Like BitCoin before it, it’s another CryptoCurrency which you can use to buy nefarious items on the DarkWeb, or perhaps ride the new electronic stock exchanges. Whatever the goal, the author of this ditty wrote the script in Bash. Yes, bash.

How do I make it stop?

Here’s what you need to know:

According to the official Raspberry Pi Magazine, it warned that there could still be millions of Raspberry Pi boards that haven’t been updated. Some 12.5 million Pi’s have been sold over the past five years. Recently, Raspberry Pi systems have sold with SSH disabled, however this doesn’t help the vast majority of the devices out there already.

Ready, steady, change that password 🙂

Exit mobile version