Threats Tagged 'cryptojacking'
View all threats tagged with 'cryptojacking'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cryptojacking'
Click on any threat for detailed analysis and mitigation recommendations
A financially motivated campaign identified in April 2026 delivers Vidar stealer and XMRig cryptocurrency miner to victims worldwide through malvertising. Attackers distribute password-protected archives impersonating cracked software, using Go-compiled loaders built with the Factory-v3 framework. The malware employs sophisticated evasion techniques including rogue Authenticode certificates mimicking JustWatch and BleacherReport, file-size inflation to hundreds of MB with null bytes, and AMSI bypass. Once executed, Vidar stealer exfiltrates browser credentials, cookies and cryptocurrency wallets to C2 infrastructure, while XMRig mines Monero cryptocurrency. The operation establishes persistence through registry modifications, scheduled tasks and startup folder scripts. The threat actor, operating under the moniker X3D MINER, primarily targets victims in the U.S. and European Union through a dual-monetization scheme combining credential theft and cryptojacking. Join the discussion | AlienVault OTX General | 07/07/2026, 23:19:29 UTC Added: 07/09/2026, 11:32:31 UTC |
Microsoft Defender Experts identified an active cryptojacking campaign leveraging AI-assisted delivery mechanisms alongside traditional SEO poisoning. Attackers create fake download sites impersonating trusted utilities like CrystalDiskInfo, HWMonitor, and FurMark, targeting users with high-performance GPUs. Victims download ZIP archives containing legitimate executables bundled with malicious DLLs that establish persistence via ScreenConnect remote access tools. The operation employs sophisticated techniques including DLL sideloading, process hollowing into Microsoft-signed .NET binaries, and comprehensive defense evasion. Beyond cryptocurrency mining, the campaign establishes persistent remote access that could enable data theft, lateral movement, or ransomware deployment. The threat actors deliberately target PC enthusiasts and hardware-focused users most likely to own discrete GPUs suitable for profitable mining operations. Join the discussion | AlienVault OTX General | 05/27/2026, 00:04:11 UTC Added: 05/27/2026, 14:03:32 UTC |
0 A global hacking campaign dubbed ShadowRay 2.0 has been discovered, exploiting a vulnerability in the Ray AI framework to seize control of computing clusters and create a self-replicating botnet. The attackers use GitLab and GitHub for payload delivery, leveraging AI-generated code to adapt their methods. The campaign has evolved from simple cryptojacking to a sophisticated multi-purpose botnet capable of DDoS attacks and data exfiltration. The operation targets exposed Ray clusters worldwide, utilizing DevOps-style infrastructure for real-time malware updates. This campaign highlights the growing attack surface in AI workloads and the risks associated with disputed vulnerabilities. Join the discussion | AlienVault OTX General | 11/19/2025, 04:25:24 UTC Added: 11/19/2025, 08:47:03 UTC |
The article discusses the evolution of cryptojacking, from its rise with Coinhive in 2017 to its apparent decline and subsequent resurgence in a more sophisticated form. A new campaign was discovered involving over 3,500 infected websites, using stealthy techniques to mine cryptocurrency without detection. The modern approach involves dropper scripts, environment checks, worker spawning, and C2 communication, prioritizing stealth over resource consumption. This new wave of cryptojacking attacks demonstrates the ongoing cat-and-mouse game between attackers and security measures, highlighting the need for continued vigilance in cybersecurity. Join the discussion | AlienVault OTX General | 08/20/2025, 10:50:59 UTC Added: 08/20/2025, 12:02:47 UTC |
A new Android malware campaign has been discovered, disguising itself as a banking app to covertly mine cryptocurrency on locked devices. The malware, distributed through a phishing website impersonating Axis Bank, downloads and executes a modified version of XMRig, a popular cryptocurrency mining software. It monitors the device's lock state and battery level, initiating mining operations when the device is locked and stopping when unlocked. This stealthy approach allows for persistent mining, leading to excessive heat generation, battery drain, and potential hardware damage. The malware uses multiple hosting platforms to distribute its payload and connects to specific mining pools. Its impact on devices includes high CPU and memory usage, significant temperature increases, and overall performance degradation. Join the discussion | AlienVault OTX General | 07/18/2025, 13:03:31 UTC Added: 07/18/2025, 20:30:58 UTC |
Showing 1 to 5 of 5 results