logo

Hidden cryptocurrency mining and theft campaign affected over 28,000 users

ID: 691083fa-4ece-586a-b1d7-c8e5c612f4fd

STIX ID: report--691083fa-4ece-586a-b1d7-c8e5c612f4fd

Feed Name: Dr.Web News

Threat Score
70/100

Date Published: 2024-10-08

Date Updated: 2026-04-27

...
...

**Executive summary:** Doctor Web identified a large-scale malware campaign distributing AutoIt-based trojans disguised as legitimate installers and system components, which deploy a stealthy cryptominer and a clipboard-clipper via encrypted self-extracting archives (hosted on GitHub/YouTube links); the malware uses IFEO persistence, process hollowing, legitimate signed DLLs with embedded scripts, and Ncat for network access, and has affected over 28,000 victims (primarily in Russia).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.