216.73.217.22

Cryptojacking Campaign Exploits Driver to Boost Monero Mining

· Published 18/02/2026 16:50 · Modified 18/02/2026 19:40

Export JSON

Essential information

Published
18/02/2026 16:50
Modified
18/02/2026 19:40
Tags
2026-02-18 CVE-2020-14979 cryptojacking driver vulnerability kernel exploit monero mining persistence pirated software stealth xmrig
Related entities
1 vulnerabilities (cve), 1 observables, 15 techniques (mitre), 1 malware, 1 others

Description

A sophisticated campaign has been discovered, spreading through installers. The operation utilizes a customized miner and a controller component for long-term system access. Unlike browser-based schemes, this campaign deploys system-level malware using deceptive installers masquerading as office software. The modular design enhances resilience, with multiple watchdog processes for . A notable feature is the exploitation of a vulnerable signed driver () to gain kernel-level access, boosting performance by 15% to 50%. The campaign connects to the Kryptex mining pool and uses a Monero wallet for payouts. Organizations are advised to enable Microsoft's vulnerable driver blocklist and implement other protective measures.

External references