PULSE NAME
A miner with a side of RAT: the unintended gift with your TV show or book
WHITE AlienVault 2026-05-28 Modified: 2026-05-28
12
IOCs
MEDIUM VOLUME
A cybercrime campaign active since at least 2022 has been distributing cryptocurrency miners and RAT malware through illegal streaming sites and digital libraries. Victims are tricked via fake video player plugin updates or browser crash pages into downloading ZIP archives containing legitimate executables and malicious DLLs. The malware employs DLL side-loading, establishes persistence through Windows services, and deploys multiple components including XMRig-based CPU miners, GPU miners, a watchdog module, and a RAT agent with remote control capabilities. The campaign leverages highly popular pirated content sites with monthly traffic reaching up to 40 million visits, significantly expanding the potential victim pool. The malware includes sophisticated anti-detection features, DNS tunneling for command-and-control, and domain generation algorithms based on dates.
Indicators of Compromise (12)
All FileHash-MD5 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 000102030405060708090a0b0c0d0e0f 2026-05-28
FileHash-MD5 0123456789abcdef0123456789abcdef 2026-05-28
FileHash-MD5 02a43b3423367b9dddc24cc7dfc070df 2026-05-28
FileHash-MD5 6a0fe6065d76715feebc1526d456db73 2026-05-28
FileHash-MD5 7f624407ae489324e96a708a09c17e6f 2026-05-28
domain 5d14vnfb.space 2026-05-28
domain jeaw520i.space 2026-05-28
domain qdmagva5.space 2026-05-28
domain r7mvjl67.space 2026-05-28
domain urush1bar4.online 2026-05-28
domain zgj1tam9.space 2026-05-28
hostname file.ipfs.us.69.mu 2026-05-28