← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
A miner with a side of RAT: the unintended gift with your TV show or book
A cybercrime campaign active since at least 2022 has been distributing cryptocurrency miners and RAT malware through illegal streaming sites and digital libraries. Victims are tricked via fake video player plugin updates or browser crash pages into downloading ZIP archives containing legitimate executables and malicious DLLs. The malware employs DLL side-loading, establishes persistence through Windows services, and deploys multiple components including XMRig-based CPU miners, GPU miners, a watchdog module, and a RAT agent with remote control capabilities. The campaign leverages highly popular pirated content sites with monthly traffic reaching up to 40 million visits, significantly expanding the potential victim pool. The malware includes sophisticated anti-detection features, DNS tunneling for command-and-control, and domain generation algorithms based on dates.
MITRE ATT&CK & Malware Families
Indicators of Compromise (6 / 12 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| domain | 5d14vnfb.space | — | 2026-05-28 | |
| domain | jeaw520i.space | — | 2026-05-28 | |
| domain | qdmagva5.space | — | 2026-05-28 | |
| domain | r7mvjl67.space | — | 2026-05-28 | |
| domain | urush1bar4.online | — | 2026-05-28 | |
| domain | zgj1tam9.space | — | 2026-05-28 |