Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
What's Hot

Trump’s anti-DEI push won’t stop black Kentucky alumni from holding off-campus celebrations

OPEC+ is in the oil price war – here’s what the cartel wants

US-UK Trade Contract: How is Trump’s global tariff talks formed? | International Trade News

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
Fyself News
Home » 2,000 Russian users infected with SilentCryptoMiner via fake VPN and DPI bypass tool
Identity

2,000 Russian users infected with SilentCryptoMiner via fake VPN and DPI bypass tool

userBy userMarch 10, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

March 10, 2025Ravi LakshmananThreat Intelligence/Cybercrime

SilentCryptominer Malware

The new mass malware campaign is infecting users with a cryptocurrency miner named SilentCryptominer by assuming it is a tool designed to bypass internet blocking and restrictions on online services.

Russian cybersecurity company Kaspersky said the activity is part of a major trend that is increasingly leveraging Windows Packet Divert (WPD) tools to distribute malware under the guise of a restriction bypass program.

“This type of software is often distributed in the form of archives with text installation instructions. Developers recommend citing false positives to break security solutions,” said researchers Leonid Bezvaenko, Dmitry Pixz and Oleg Kuplev. “This is something that is in the hands of an attacker by allowing an attacker to last in an unprotected system without the risk of detection.”

Cybersecurity

This approach has been used as part of schemes that propagate steelers, remote access tools (rats), Trojan horses that provide hidden remote access, and cryptocurrency miners such as NJRAT, XWORM, PHEMEDRONE, and DCRAT.

The latest twist on this tactic is a campaign that compromised over 2,000 Russian users with miners who disguise themselves as tools to remove blocks based on deep packet inspection (DPI). The program is said to have been promoted in the form of links to malicious archives via a YouTube channel with 60,000 subscribers.

SilentCryptominer Malware

A subsequent escalation of tactics discovered in November 2024 led to such tool developers threatening channel owners with notifications of fake copyright strikes, and threat actors have been discovered who have asked to post videos with malicious links or risk shutting down the channel due to assumptions of infringement.

“And in December 2024, users reported the distribution of versions infected with miners of the same tool via other telegrams and YouTube channels.

The booby trapped archive is known to pack additional executables using one of the legitimate batch scripts that have been modified to run the binary via PowerShell. If anti-virus software installed on your system interferes with the attack chain and removes malicious binaries, the user will receive an error message that prompts them to re-download the file and disable the security solution before running it.

Cybersecurity

The executable is a Python-based loader designed to get another Python script that downloads the payload of the SilentCryptominer minor and establishes persistence, another Python script, but not before you check if it runs in a sandbox and configures Windows Defender exclusion.

Minors based on the open source minor XMRIG padded with random data to artificially inflate the file size to 690 MB, ultimately preventing automatic analysis by antivirus solutions and sandboxes.

“In Stealth, SilentCryptominer employs a process to inject minor code into the system process (in this case DWM.EXE),” says Kaspersky. “Malware can stop mining while the process specified in the configuration is active. It can be controlled remotely via the web panel.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous Article“Quiet, Little Man”: Polish FM and Musk clash through Ukrainian Starlink | Internet News
Next Article Neom is McKinsey & Co. Except for this, it is reportedly turned into a financial disaster.
user
  • Website

Related Posts

SONICWALL Patch 3 flaws in SMA 100 devices allow attackers to execute code as root

May 8, 2025

Qilin ransomware ranked best in April 2025 with over 45 data leak disclosures

May 8, 2025

Security tools alone won’t protect you – the control effect

May 8, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Trump’s anti-DEI push won’t stop black Kentucky alumni from holding off-campus celebrations

OPEC+ is in the oil price war – here’s what the cartel wants

US-UK Trade Contract: How is Trump’s global tariff talks formed? | International Trade News

Bill Gates says he will hand out 99% of his wealth by 2045 | Charity News

Trending Posts

US-UK Trade Contract: How is Trump’s global tariff talks formed? | International Trade News

May 8, 2025

Bill Gates says he will hand out 99% of his wealth by 2045 | Charity News

May 8, 2025

Ukrainian parliament criticizes contracts with us for landmark mineral trade in Russia-Ukraine War News

May 8, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Did Figma kill Webflow and Framer with the release of the Figma site?

Metaworld Congress 2025: Madrid Takes Center Stage in Digital Innovation

Coinbase wins DeRibit for $2.9 billion and earns a major push to crypto derivatives

Former Synapse CEO resurfaces with new humanoid robot startup aiming to valuate $1 billion

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.