logo

It’s a trap: Detecting a cryptominer on a popular website using Group-IB MXDR

ID: 0a320eeb-ea62-5b32-86f5-cf40964a8b58

STIX ID: report--0a320eeb-ea62-5b32-86f5-cf40964a8b58

Feed Name: Group-IB Blog

Threat Score
60/100

Date Published: 2023-09-22

Date Updated: 2026-04-27

...
...

Group-IB uncovered a cryptojacking campaign that abused a popular online thesaurus to silently serve obfuscated scripts which trigger a drive-by download of zip archives (named like chromium-patch-nightly.*) containing a dropper that deploys the XMRig Monero miner; the attack used IPFS/Pinata-hosted payloads and a fake Chrome error page to social-engineer users into downloading the malicious archive. Group-IB detected and analyzed the files with MXDR/EDR and a Malware Detonation Platform, found no evidence the droppers executed on monitored hosts, and provided containment and prevention recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.