A new threat actor is offering an enhanced version of HiddenMiner, an advanced cryptocurrency mining malware that targets Monero (XMR).
See also: Malicious VSCode extensions infect Windows with cryptominer

This custom tool, which is available for sale on underground forums, combines advanced detection evasion techniques with a user-friendly interface, potentially lowering the barrier to entry for would-be cybercriminals.
Unlike traditional mining malware, HiddenMiner incorporates several technical improvements aimed at maximizing profit and minimizing the risk of detection and removal. Its latest version is advertised with a host of features that ensure persistence and detection evasion.
According to forum posts, the malware features a one-click installation process, allowing even technically inexperienced threat actors to install it efficiently. The combination of stealth capabilities with simplified installation significantly increases the chances of HiddenMiner being distributed on a mass scale.
The malware uses virtual machine bypass (AntiVM) techniques to detect if it is running in virtual environments, such as those used by security researchers and sandboxes.
When HiddenMiner detects an analysis environment, it modifies its behavior to appear harmless, making detection by automated analysis tools more difficult. One of its most concerning features is its ability to run without administrator rights, yet still manage to gain elevated privileges.
See also: SilentCryptoMiner has infected 2,000 Russian users
The malware exploits Windows User Account Control (UAC) bypass techniques to gain elevated privileges without triggering security alerts.

HiddenMiner uses rootkit to hide its activities on infected systems. The malware has the ability to hide both processes and folders through advanced obfuscation methods, making it extremely difficult for users to detect its presence.
According to forum advertisements, HiddenMiner actively blocks antivirus programs, security scanners, and popular analysis tools.
The cryptominer has a persistent auto-download feature, which allows it to remain active even after a system reboot. Upon Windows startup, the malware automatically activates, continuing its cryptocurrency mining.
HiddenMiner is offered at a price ranging from $40 to $100, depending on the features selected. The threat actor also advertises optional add-ons, such as dual mining (XMR + ETH), for an additional cost of $30.
See also: StaryDobry: New malware campaign infects gamers with cryptominer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
A significant element that emerges from the above is the increasing professionalization of cybercrime, as tools such as HiddenMiner are now available as “off-the-shelf solutions” on underground forums. The detection evasion techniques, the ability to run without administrator rights, and the ease of one-click installation mean that even individuals with limited knowledge can exploit this type of malware. This reinforces the need for more sophisticated detection and protection methods, both at the end-user level and in enterprise environments.
Source: cybersecuritynews
