Crypto-stealing malware campaign infects 28,000 people
ID: e4494310-f641-5266-a6ae-1e2ae8570f6e
STIX ID: report--e4494310-f641-5266-a6ae-1e2ae8570f6e
Feed Name: Bleeping Computer
**Executive summary:** Dr.Web reported a large-scale malware campaign affecting over 28,000 users (primarily in Russia and neighboring countries) that delivers a modified .NET-based cryptominer and a 7-Zip-based clipboard clipper via password-protected archives promoted on YouTube and fake GitHub pages; the malware employs anti-analysis checks, IFEO persistence (hijacking system and browser update processes), disables recovery, revokes file permissions, and uses Ncat/Telegram for C2 and data exfiltration, with confirmed monetary theft from clipboard hijacking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
