Cybercriminals are distributing sophisticated cryptocurrency miners through illegal streaming and digital library websites by tricking users into installing fake video player plugin updates that trigger DLL side-loading.
Key Points
- The malware uses a ZIP archive containing a legitimate executable and a malicious DLL to inject mining code into system processes.
- Attackers target high-traffic pirated content sites, with associated websites recording approximately 40 million visits in April 2026.
- The campaign employs a modified version of the SilentCryptoMiner project, utilizing DNS tunneling and process hollowing to evade detection.
- Persistence is maintained by disabling Windows security tools, such as the Malicious Software Removal Tool, and creating unauthorized system services.
- The modular malware includes a Remote Access Trojan (RAT) capable of executing arbitrary commands and shellcode on compromised devices.