logo

Multicomponent Malware Targeting Cryptocurrency

ID: f575f922-ac9d-51d1-9bc3-24bbc0c0e4cc

STIX ID: report--f575f922-ac9d-51d1-9bc3-24bbc0c0e4cc

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

**Executive summary:** Zscaler ThreatLabZ identified a downloader that persists under AppData, fetches and deploys a password stealer and a Monero/Aeon coinminer (injecting into explorer.exe), exfiltrates browser credentials via email attachments, and mines cryptocurrency using listed pool endpoints and infrastructure; notable IoCs include https://leletorrents.info/22112995, https://crackpoint.xyz/22112995, and IP 159.89.88.49:14254.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.