logo

StaryDobry ruins New Year’s Eve, delivering miner instead of presents

ID: 3b5a99fd-b13d-5605-ad10-8e8c56367b63

STIX ID: report--3b5a99fd-b13d-5605-ad10-8e8c56367b63

Feed Name: Securelist by Kaspersky

Threat Score
70/100

Date Published: 2025-02-18

Date Updated: 2026-04-29

Author: Tatyana Shishkova, Kirill Korchemny

...
...

Kaspersky telemetry identified a global campaign (StaryDobry) distributing trojanized game repacks on torrent sites to install a multi-stage loader that ultimately deploys a modified XMRig cryptominer; the chain uses Inno Setup installers, an unrar.dll dropper, a thumbnail-handler DLL (MTX64), a kickstarter loader, injection techniques, resource and timestamp spoofing, scheduled tasks for persistence, and C2 infrastructure (promouno.shop, pinokino.fun and 45.200.149.*). The campaign targets gaming-capable machines (checks CPU cores before mining), employs multiple anti-analysis and defense-evasion techniques, and has been observed primarily in Russia with additional infections in Belarus, Kazakhstan, Germany and Brazil; the report includes file hashes, domains and IPs as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.