logo

Wormable XMRig Campaign Uses BYOVD Exploit and Time-Based Logic Bomb

ID: 582c3cf3-d844-5934-b198-72a4aa205353

STIX ID: report--582c3cf3-d844-5934-b198-72a4aa205353

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-02-23

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Cybersecurity researchers disclosed a sophisticated cryptojacking campaign that lures victims with pirated software bundles to deploy a multi‑stage XMRig miner capable of privilege escalation via a vulnerable driver (WinRing0x64.sys, CVE-2020-14979), persistent 'circular watchdog' mechanisms, and worm-like spread through removable media; separate reporting also links LLM-generated exploit code and the ILOVEPOOP toolkit to exploitation of the high‑severity React2Shell vulnerability (CVE-2025-55182), which has been used to compromise dozens to over ninety hosts across government, defense, finance, and industrial sectors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.