logo

Doctor, where did you get these pictures? Using steganography in a cryptocurrency mining campaign.

ID: eb907446-4779-5f21-824a-266abd0ad43d

STIX ID: report--eb907446-4779-5f21-824a-266abd0ad43d

Feed Name: Dr.Web News

Threat Score
70/100

Date Published: 2025-01-24

Date Updated: 2026-04-27

...
...

Doctor Web analyzes an active Monero-mining campaign (observed since 2022) that distributes SilentCryptoMiner and related modules via multi-stage chains including a .NET loader, VBScript/PowerShell downloaders, and a steganography-based delivery that extracts executables from BMP images hosted on legitimate services; the campaign also deploys a .NET stealer, disables UAC/Windows Defender, uses DNS TXT and GitHub for payload delivery, includes sandbox/VM detection, and has so far credited a wallet with ~340 XMR (~$65–70k).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.