Skip to main content

Threats Tagged 'cryptocurrency mining'

View all threats tagged with 'cryptocurrency mining'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cryptocurrency mining

Threats Tagged 'cryptocurrency mining'

Click on any threat for detailed analysis and mitigation recommendations

A sophisticated multi-stage infection chain was discovered through analysis of a system exhibiting frequent PowerShell execution alerts. The attack leveraged multiple layers of obfuscation and concealment techniques, including Registry-based payload storage, DNS TXT record exploitation, and data hidden within image and WAV audio files. The threat actors employed various evasion methods such as security control tampering and in-memory execution to avoid detection. Rather than writing payloads directly to disk, attackers reconstructed malicious code from distributed sources including Registry entries and steganographically encoded data in media files. The ultimate objective of this elaborate infection chain was to deploy cryptocurrency mining operations covertly on compromised systems while maintaining persistent access through multiple redundant mechanisms.

Join the discussion

A sophisticated backdoor disguised as a legitimate Malwarebytes installer was distributed to over 100,000 machines through compromised automatic updates of one torrent client (Download Studio) and three adblockers (NetShield Kit, My AdBlock, and Net AdBlock). The backdoor creates a fake Malwarebytes installation directory containing legitimate signed files alongside malicious DLL files. Once executed, it establishes persistence through a Windows service and communicates with command-and-control servers to receive configuration updates and additional payloads. The primary observed payloads were cryptocurrency miners, though the infrastructure supports delivery of multiple persistent threats. The attack demonstrates abuse of software update mechanisms and affects primarily users in Russia, Ukraine, and Kazakhstan.

Join the discussion

Aeternum is a C++ botnet loader utilizing the Polygon blockchain for command-and-control infrastructure instead of traditional centralized servers. Threat actors write encrypted and plaintext instructions directly to smart contracts, which infected devices query via public RPC endpoints. The malware implements weak PBKDF2HMAC/AES-GCM encryption with self-salting passwords, allowing payload decryption using only the smart contract address. Analysis reveals three related samples: the core Aeternum loader with Telegram-based exfiltration, a blended threat combining XWorm RAT with XMRig cryptocurrency miner, and Python source code revealing anti-analysis checks and cryptocurrency wallet targeting. The botnet demonstrates resilience through decentralized infrastructure, making traditional law enforcement takedowns significantly more challenging while maintaining low operational costs for attackers.

Join the discussion
0

GhostGrab is a sophisticated Android malware that combines cryptocurrency mining with extensive data theft, targeting sensitive financial information such as banking credentials, debit card details, and OTPs. It exploits device resources for mining while maintaining persistence through advanced hiding techniques and resisting removal. The malware abuses permissions to access SMS, calls, and storage, enabling comprehensive data exfiltration. It uses Firebase for command-and-control and data exfiltration, masking malicious activity within legitimate cloud traffic. Its modular design includes WebView-based phishing pages aimed at financial fraud and identity theft. The malware infrastructure involves recently registered domains and obfuscation services, indicating a professional operation. GhostGrab exemplifies the convergence of financial cybercrime and resource exploitation in mobile malware, posing a significant threat to Android users. European organizations with mobile banking users are at risk, especially where Android market share is high. Mitigation requires enhanced mobile security controls, user awareness, and network monitoring for suspicious Firebase traffic.

Join the discussion

Blitz is a new Windows-based malware discovered in 2024 consisting of a downloader and bot payload. The latest version was spread through backdoored game cheats for Standoff 2 distributed via Telegram. Blitz abuses Hugging Face Spaces to host components of its C2 infrastructure and payloads. The malware performs information stealing and DDoS attacks. An XMRig cryptocurrency miner was also deployed as follow-up malware. By May 2025, the developer claimed to have abandoned the project. Russia accounted for the highest number of infections among 289 victims across 26 countries. Palo Alto Networks customers are protected through various security products and services.

Join the discussion

A series of attacks targeting Korean Internet cafés have been identified, focusing on systems with specific management software installed. The threat actor, active since 2022, uses Gh0st RAT for system control and ultimately installs T-Rex CoinMiner for cryptocurrency mining. The initial access method remains unknown. The attacks involve memory patching of management software and use of downloaders. The malware suite includes Gh0st RAT, its droppers, patchers, downloaders, and T-Rex CoinMiner. Unlike typical coin mining operations using XMRig for Monero, this actor employs T-Rex, likely due to the presence of high-performance GPUs in Internet café PCs. The attacks have been ongoing since late 2024, prompting responses from management software manufacturers.

Join the discussion

A new Dero mining campaign is infecting containerized Linux environments through exposed Docker APIs. The attack uses two Golang malware components: 'nginx' for propagation and 'cloud' for mining. The 'nginx' malware scans for vulnerable Docker hosts, creates malicious containers, and compromises existing ones. It maintains persistence and spreads without a command-and-control server. The 'cloud' component is a modified DeroHE CLI miner with hardcoded wallet and node addresses. This campaign demonstrates the potential risks of insecurely published Docker APIs and the need for robust container security measures.

Join the discussion

A new Dero mining campaign exploits insecurely published Docker APIs to spread through containerized Linux environments. The attack uses two Golang malware implants: 'nginx' for propagation and 'cloud' for cryptocurrency mining. The 'nginx' malware scans for vulnerable Docker APIs, creates malicious containers, and compromises existing ones. It maintains persistence and spreads without a command-and-control server. The 'cloud' miner is based on the open-source DeroHE CLI project, with hardcoded wallet and node addresses. This campaign differs from previous attacks on Kubernetes clusters by actively spreading and compromising more networks. The threat highlights the importance of securing containerized infrastructures and monitoring for malicious activities.

Join the discussion

Showing 1 to 8 of 8 results

Filters:Tag: cryptocurrency mining
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses