AUTO-UPDATED

Pirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for years

Cybercriminals are distributing sophisticated cryptocurrency miners through illegal streaming and digital library websites by tricking users into installing fake video player plugin updates that trigger DLL side-loading.

Key Points

  • The malware uses a ZIP archive containing a legitimate executable and a malicious DLL to inject mining code into system processes.
  • Attackers target high-traffic pirated content sites, with associated websites recording approximately 40 million visits in April 2026.
  • The campaign employs a modified version of the SilentCryptoMiner project, utilizing DNS tunneling and process hollowing to evade detection.
  • Persistence is maintained by disabling Windows security tools, such as the Malicious Software Removal Tool, and creating unauthorized system services.
  • The modular malware includes a Remote Access Trojan (RAT) capable of executing arbitrary commands and shellcode on compromised devices.

Why it Matters

This campaign demonstrates how threat actors exploit the popularity of pirated content to achieve massive distribution scales while continuously evolving their evasion techniques. By compromising system integrity and disabling security features, these miners impose significant performance costs on victims and provide attackers with persistent remote control over infected machines.
Securelist.com Published by Konstantin Krasilnikov, Valery Akulenko, Artem Snegirev
Read original