HomeSecurityStaryDobry: New malware campaign infects gamers with cryptominer

StaryDobry: New malware campaign infects gamers with cryptominer

A new malware campaign, dubbed “StaryDobry,” is targeting gamers around the world with trojanized versions of cracked games like Garry’s Mod, BeamNG.drive, and Dyson Sphere Program. These are popular games with hundreds of thousands of positive reviews on Steam.

StaryDobry malware gamers with cryptominer Garry's Mod

According to Kaspersky, the StaryDobry campaign began in late December 2024 and infected gamers until January 27, 2025. It mainly affected users from Germany, Russia, Brazil, Belarus, and Kazakhstan.

The attackers uploaded infected game installers to torrent sites in September 2024. However, they activated the payloads within the games during the Christmas holidays, to hide the malicious activity more effectively.

See also: New FrigidStealer malware targets macOS systems

StaryDobry: Trojanized cracked games infect gamers with malware

According to researchers, the StaryDobry campaign used a multi-stage infection chain that leads to the infection of users with an XMRig cryptominer.

Users downloaded the trojanized game installers from torrent sites, which appeared to be legitimate. However, users were downloading the regular game along with malicious code.

During the game installation, the malware dropper (unrar.dll) would start running in the background and check if it was running in a virtual machine, sandbox, or debugger. If a security tool, it would stop running .

The malware then registered itself using “regsvr32.exe” for persistence and began collecting detailed system, including operating system version, country, CPU, RAM, and GPU. This information was sent to the command and control (C2) server at pinokino[.]fun.

See also: New XCSSET malware attacks macOS users and Xcode projects

Eventually, the dropper decrypted and installed the malware loader (MTX64.exe) in a system directory.

The loader was presented as a Windows system file and created a scheduled task to maintain persistence across reboots. If the host computer had at least eight CPU cores, it would download and run an XMRig miner.

StaryDobry: New malware campaign infects gamers with cryptominer

The XMRig miner used in the StaryDobry malware campaign is a modified version of the Monero miner that constructs its parameters internally before execution (it has no access to arguments). The miner maintains a separate thread at all times, monitoring security tools running on the infected machine. If process monitoring tools are detected, it shuts itself down.

The XMRig used in these attacks is connected to private mining servers instead of public pools. As a result, tracing the earnings becomes more difficult.

Kaspersky was unable to attribute the attacks to any known threat group. However, it did observe that the attackers used popular free games as bait to target gamers, who typically have powerful machines that can withstand cryptomining activity.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: FINALDRAFT Malware Exploits Microsoft Graph API

As the popularity of games continues to grow, so does the risk of being targeted by malicious hackers. can Free games be tempting, but it's essential to be cautious when downloading from unofficial sources. In addition to malware infections, cracked games can also expose you to other risks, such as data theft and financial fraud.

The “StaryDobry” malware campaign serves as a reminder of the ongoing threat posed by cybercrime and the importance of remaining vigilant when using technology. By being cautious when downloading games or software from untrusted sources, keeping systems and applications up to date, and regularly learning about cybersecurity best practices, we can better protect ourselves from such attacks. It is also important for the broader gaming community to work together to combat cybercrime and create a safer digital landscape for everyone.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS