Cryptojacking Campaign Exploits Driver to Boost Monero Mining
ID: 75b848a4-b9ab-5f6a-8c2e-e49d0a2993f2
STIX ID: report--75b848a4-b9ab-5f6a-8c2e-e49d0a2993f2
Feed Name: Infosecurity Magazine (News)
**Executive summary:** Trellix uncovered a modular cryptojacking campaign distributed through pirated installers that installs a controller (Explorer.exe), multiple persistence watchdogs and a customised XMRig miner; it uses a signed vulnerable driver (WinRing0x64.sys, CVE-2020-14979) to obtain kernel access and disable CPU prefetchers to boost Monero RandomX hash rates, connects to a Kryptex mining pool for payouts, and contains a hardcoded expiration (December 23, 2025).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
