HomeSecuritySilentCryptoMiner has infected 2,000 Russian users

SilentCryptoMiner has infected 2,000 Russian users

A new malware campaign is infecting users with SilentCryptoMiner, a crypto miner that is presented as a tool that bypasses internet blocks and restrictions around various online services.

SilentCryptoMiner crypto miner malware

According to Russian cybersecurity firm Kaspersky, this activity is part of a broader trend where cybercriminals are leveraging Windows Packet Divert (WPD) tools to distribute malware disguised as restriction bypassers.

“ Such software is often distributed in the form of archives with text-based installation instructions, where developers recommend disabling security solutionsdue to false positives ,” researchers Leonid Bezvershenko, Dmitry Pikush, and Oleg Kupreev said . Thus, attackers can remain on an unprotected system without the risk of detection.

See also: StaryDobry: New malware campaign infects gamers with cryptominer

This method has been used to distribute various malware. The most recent campaign, which has compromised more than 2,000 Russian users, distributed SilentCryptoMiner, a crypto miner disguised as a tool that supposedly bypasses deep packet inspection (DPI) restrictions. The program was advertised as a link to a malicious archive, via a YouTube channel with 60,000 subscribers.

Also, some users reported the distribution of a version of the same tool through other Telegram and YouTube, which have now been shut down.

The booby-trapped archives appear to contain an additional executable file, with one of the legitimate batch scripts modified to execute the binary via PowerShell. In case the antivirus software installed on the system intervenes in the attack chain and deletes the malicious binary, users see an error message. This message prompts them to download the file again and run it after disabling their security solutions.

See also: Polyglot malware: What it is and how to protect yourself

The executable is a Python-based loader designed to retrieve a next-stage malware, another Python script, which ultimately downloads the SilentCryptoMiner miner payload. At this stage, persistence is also established, but first a check is made to see if it is running in a sandbox.

SilentCryptoMiner has infected 2,000 Russian users

The crypto miner, based on the open-source miner XMRig, contains random blocks of data to artificially increase the file size to 690 MB and ultimately prevent automatic analysis by antivirus solutions and sandboxes.

“For stealth, SilentCryptoMiner uses a hollowing process to inject mining code into a system process (in this case, dwm.exe),” Kaspersky said. “The malware can stop mining while the processes specified in the configuration are active. It can be controlled remotely via a web dashboard.”

This campaign is particularly dangerous because it exploits users who search for tools to bypass restrictions, a tactic that facilitates attackers in distributing SilentCryptoMiner.

See also: BackConnect malware links Black Basta and Cactus ransomware

Protection tips

  • Avoid downloading unverified software
  • Check the authenticity of the file
  • Keep your system and software up to date
  • Monitor your system for suspicious behavior
  • Enable the firewall and use ad-blocking programs
  • Avoid cracked software and free software from unknown sources
  • Use a strong, up-to-date security suite
  • Be careful with browser extensions

Source: thehackernews.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS