A new malware campaign is infecting users with SilentCryptoMiner, a crypto miner that is presented as a tool that bypasses internet blocks and restrictions around various online services.

According to Russian cybersecurity firm Kaspersky, this activity is part of a broader trend where cybercriminals are leveraging Windows Packet Divert (WPD) tools to distribute malware disguised as restriction bypassers.
“ Such software is often distributed in the form of archives with text-based installation instructions, where developers recommend disabling security solutionsdue to false positives ,” researchers Leonid Bezvershenko, Dmitry Pikush, and Oleg Kupreev said . Thus, attackers can remain on an unprotected system without the risk of detection.
See also: StaryDobry: New malware campaign infects gamers with cryptominer
This method has been used to distribute various malware. The most recent campaign, which has compromised more than 2,000 Russian users, distributed SilentCryptoMiner, a crypto miner disguised as a tool that supposedly bypasses deep packet inspection (DPI) restrictions. The program was advertised as a link to a malicious archive, via a YouTube channel with 60,000 subscribers.
Also, some users reported the distribution of a version of the same tool through other Telegram and YouTube, which have now been shut down.
The booby-trapped archives appear to contain an additional executable file, with one of the legitimate batch scripts modified to execute the binary via PowerShell. In case the antivirus software installed on the system intervenes in the attack chain and deletes the malicious binary, users see an error message. This message prompts them to download the file again and run it after disabling their security solutions.
See also: Polyglot malware: What it is and how to protect yourself
The executable is a Python-based loader designed to retrieve a next-stage malware, another Python script, which ultimately downloads the SilentCryptoMiner miner payload. At this stage, persistence is also established, but first a check is made to see if it is running in a sandbox.

The crypto miner, based on the open-source miner XMRig, contains random blocks of data to artificially increase the file size to 690 MB and ultimately prevent automatic analysis by antivirus solutions and sandboxes.
“For stealth, SilentCryptoMiner uses a hollowing process to inject mining code into a system process (in this case, dwm.exe),” Kaspersky said. “The malware can stop mining while the processes specified in the configuration are active. It can be controlled remotely via a web dashboard.”
This campaign is particularly dangerous because it exploits users who search for tools to bypass restrictions, a tactic that facilitates attackers in distributing SilentCryptoMiner.
See also: BackConnect malware links Black Basta and Cactus ransomware
Protection tips
- Avoid downloading unverified software
- Check the authenticity of the file
- Keep your system and software up to date
- Monitor your system for suspicious behavior
- Enable the firewall and use ad-blocking programs
- Avoid cracked software and free software from unknown sources
- Use a strong, up-to-date security suite
- Be careful with browser extensions
Source: thehackernews.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
