StaryDobry ruins New Year’s Eve, delivering miner instead of presents
ID: 3b5a99fd-b13d-5605-ad10-8e8c56367b63
STIX ID: report--3b5a99fd-b13d-5605-ad10-8e8c56367b63
Feed Name: Securelist by Kaspersky
Kaspersky telemetry identified a global campaign (StaryDobry) distributing trojanized game repacks on torrent sites to install a multi-stage loader that ultimately deploys a modified XMRig cryptominer; the chain uses Inno Setup installers, an unrar.dll dropper, a thumbnail-handler DLL (MTX64), a kickstarter loader, injection techniques, resource and timestamp spoofing, scheduled tasks for persistence, and C2 infrastructure (promouno.shop, pinokino.fun and 45.200.149.*). The campaign targets gaming-capable machines (checks CPU cores before mining), employs multiple anti-analysis and defense-evasion techniques, and has been observed primarily in Russia with additional infections in Belarus, Kazakhstan, Germany and Brazil; the report includes file hashes, domains and IPs as IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
