It’s a trap: Detecting a cryptominer on a popular website using Group-IB MXDR
ID: 0a320eeb-ea62-5b32-86f5-cf40964a8b58
STIX ID: report--0a320eeb-ea62-5b32-86f5-cf40964a8b58
Feed Name: Group-IB Blog
Group-IB uncovered a cryptojacking campaign that abused a popular online thesaurus to silently serve obfuscated scripts which trigger a drive-by download of zip archives (named like chromium-patch-nightly.*) containing a dropper that deploys the XMRig Monero miner; the attack used IPFS/Pinata-hosted payloads and a fake Chrome error page to social-engineer users into downloading the malicious archive. Group-IB detected and analyzed the files with MXDR/EDR and a Malware Detonation Platform, found no evidence the droppers executed on monitored hosts, and provided containment and prevention recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
