Crypto-stealing malware campaign infects 28,000 people

Share:

Over 28,000 people from Russia, Turkey, Ukraine, and other countries in the Eurasian region were impacted by a large-scale cryptocurrency-stealing malware campaign.

The malware campaign disguises itself as legitimate software promoted via YouTube videos and fraudulent GitHub repositories where victims download password-protected archives that initiate the infection.

According to cybersecurity firm Dr. Web, the campaign uses pirated office-related software, game cheats and hacks, and even automated trading bots to deceive users into downloading malicious files.

“In total, this malware campaign has affected more than 28,000 people, the vast majority of whom are residents of Russia,” said Dr. Web.

“Significant numbers of infections have also been observed in Belarus, Uzbekistan, Kazakhstan, Ukraine, Kyrgyzstan and Turkey.”

Infection chain

The infection begins with opening a self-extracting archive that evades antivirus scans when downloaded as it’s password-protected.

After the victim enters the provided password, the archive drops various obfuscated scripts, DLL files, and an AutoIT interpreter used to launch the digitally signed loader of the main payload.

The malware checks for the presence of debugging tools to see if it’s running on an analyst’s environment and terminates if any are found.

Next, it extracts the files required for the subsequent stages of the attack and then uses the Image File Execution Options (IFEO) technique to modify the Windows Registry for persistence.

In short, it hijacks legitimate Windows system services as well as Chrome’s and Edge’s update processes with malicious ones, so the malware files are executed upon the launch of these processes.

The Windows Recovery Service is disabled, and the “delete” and “modify” permissions on the malware’s files and folders are revoked to prevent attempted cleanups.

From there on, the Ncat network utility is employed to establish communication with the command and control (C2) server.

The malware can also collect system information, including running security processes, which it exfiltrates via a Telegram bot.

Complete attack chain
Complete attack chain
Source: Dr. Web

Financial impact

The campaign delivers two key payloads onto the victims’ machines. The first one is “Deviceld.dll,” a modified .NET library used to execute the SilentCryptoMiner, which mines cryptocurrency using the victim’s computational resources.

The second payload is “7zxa.dll,” a modified 7-Zip library that acts as a clipper, monitoring the Windows clipboard for copied wallet addresses and replacing them with addresses under the attacker’s control.

Dr. Web did not specify in the report the potential mining profits from the 28,000 infected machines but found that the clipper alone had hijacked $6,000 worth of transactions, diverting the amount onto the attacker’s addresses.

To avoid unexpected financial losses, only download software from the project’s official website and block or skip promoted results on Google Search.

Furthermore, be careful of shared links on YouTube or GitHub, as the legitimacy of these platforms does not guarantee the download destination’s safety.

Bill Toulas

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
4:23 pm, Jun 12, 2025
weather icon 24°C
L: 23° | H: 26°
broken clouds
Humidity: 63 %
Pressure: 1011 mb
Wind: 11 mph S
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 75%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:43 am
Sunset: 9:17 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
23° | 26°°C 0 mm 0% 9 mph 71 % 1014 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
16° | 27°°C 1 mm 100% 7 mph 94 % 1019 mb 0 mm/h
Sat Jun 14 10:00 pm
weather icon
17° | 23°°C 1 mm 100% 13 mph 96 % 1019 mb 0 mm/h
Sun Jun 15 10:00 pm
weather icon
13° | 22°°C 0.46 mm 46% 10 mph 84 % 1025 mb 0 mm/h
Mon Jun 16 10:00 pm
weather icon
14° | 25°°C 0 mm 0% 7 mph 86 % 1027 mb 0 mm/h
Today 7:00 pm
weather icon
24° | 24°°C 0 mm 0% 9 mph 62 % 1011 mb 0 mm/h
Today 10:00 pm
weather icon
19° | 21°°C 0 mm 0% 4 mph 71 % 1014 mb 0 mm/h
Tomorrow 1:00 am
weather icon
17° | 17°°C 0 mm 0% 3 mph 80 % 1016 mb 0 mm/h
Tomorrow 4:00 am
weather icon
16° | 16°°C 0 mm 0% 3 mph 84 % 1017 mb 0 mm/h
Tomorrow 7:00 am
weather icon
18° | 18°°C 0 mm 0% 7 mph 79 % 1018 mb 0 mm/h
Tomorrow 10:00 am
weather icon
22° | 22°°C 0 mm 0% 7 mph 60 % 1019 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
26° | 26°°C 0 mm 0% 6 mph 41 % 1019 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
27° | 27°°C 0 mm 0% 7 mph 40 % 1019 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,843.15
-1.94%
Ethereum(ETH)
€2,385.76
-2.48%
Tether(USDT)
€0.86
0.00%
XRP(XRP)
€1.94
-3.26%
Solana(SOL)
€137.78
-3.91%
USDC(USDC)
€0.86
0.00%
Dogecoin(DOGE)
€0.163467
-6.01%
Shiba Inu(SHIB)
€0.000011
-5.69%
Pepe(PEPE)
€0.000010
-5.84%
Peanut the Squirrel(PNUT)
€0.236997
-5.02%
Scroll to Top