logo

XMRig CoinMiner Installed via Game Hacks

ID: 20dbf6f0-7aea-536f-9b1b-f53ce970e5b5

STIX ID: report--20dbf6f0-7aea-536f-9b1b-f53ce970e5b5

Feed Name: ASEC

Threat Score
65/100

Date Published: 2024-01-25

Date Updated: 2026-04-26

Author: kwonxx

...
...

AhnLab ASEC reports XMRig CoinMiner being distributed through game-hack websites: compressed archives include a downloader (AutoHotkey), tools to disable Windows Defender (dControl.exe), and loader.exe which installs the miner to %ProgramData% and %temp%, edits hosts, disables update/MSRT services, and persists as a service named GoogleUpdateFile; the report includes file hashes and a download URL and warns users against running executables from untrusted game-hack sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.