216.73.216.233

SilentCryptoMiner distributed as a bypass tool

· Published 05/03/2025 11:12 · Modified 05/03/2025 16:40

Export JSON

Essential information

Published
05/03/2025 11:12
Modified
05/03/2025 16:40
Tags
2025-03-05 blackmail cryptocurrency mining dcrat njrat phemedrone python loader restriction bypass silentcryptominer stealth techniques xmrig xworm
Related entities
20 techniques (mitre), 5 malware

Description

A mass malware campaign is infecting users with a cryptocurrency miner disguised as a tool for bypassing internet restrictions. The campaign has affected over 2,000 victims in Russia, utilizing YouTube channels to spread malicious links. Attackers are blackmailing content creators to post videos with infected file links, threatening channel shutdowns. The malware uses a multi-stage infection process, including a that downloads and executes the . This miner, based on , employs like process hollowing and can mine various cryptocurrencies. The campaign highlights the growing exploitation of tools for malware distribution, posing significant risks to user data security.

External references