Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Elon Musk battles Grok safety claims before SpaceX debut

June 13, 2026

How $48 mln vanished from Tron to Monero before Tether could stop it

June 13, 2026

Goldman Sachs Sees Fed Delaying Rate Cuts This Year – Here’s When the Next One Is Coming

June 13, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Massive Coin-Mining Attempt Targets Nearly Half a Million PCs
Massive Coin-Mining Attempt Targets Nearly Half a Million PCs
Security and Privacy

Massive Coin-Mining Attempt Targets Nearly Half a Million PCs

September 4, 2023No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Microsoft has averted a massive and widespread campaign that would have seen tens of thousands of machines impacted.

The software giant reported that on March 6, “Windows Defender AV blocked more than 80,000 instances of several sophisticated Trojans that exhibited advanced cross-process injection techniques, persistence mechanisms and evasion methods.” The Trojans, which are new variants of Dofoil (also known as Smoke Loader), carry a coin-miner payload. “Within the next 12 hours, more than 400,000 new instances were recorded, 73% of which were in Russia. Turkey accounted for 18% and Ukraine 4%,” Microsoft stated.

Dofoil uses a customized mining application that supports a function called NiceHash, which means it can mine different cryptocurrencies. The samples Microsoft analyzed mined Electroneum coins. It burrowed into systems using a process called process hollowing.

“Process hollowing is a code injection technique that involves spawning a new instance of legitimate process…and then replacing the legitimate code with malware,” explained Mark Simos, lead cybersecurity architect for Microsoft’s enterprise cybersecurity group in a blog. “The hollowed explorer.exe process then spins up a second malicious instance, which drops and runs a coin mining malware masquerading as a legitimate Windows binary.”

The attack was picked up on thanks to its use of an unusual persistence mechanism, which triggered behavior-based alerts. For coin-miner malware, it’s required to stay undetected for long periods in order to mine enough coins to make the attack worth its while.

In this case, Dofoil modifies the registry.

“The hollowed explorer.exe process creates a copy of the original malware in the Roaming AppData folder and renames it to ditereah.exe,” Simos said. “It then creates a registry key or modifies an existing one to point to the newly created malware copy. In the sample we analyzed, the malware modified the OneDrive Run key.”

See also  Hackers Raid Crypto Firms in $25m Attacks

Dofoil is only the latest malware family to incorporate coin miners in attacks; it’s becoming a popular payload thanks to the skyrocketing value of Bitcoin and other cryptocurrencies. Exploit kits are now delivering coin miners instead of ransomware, scammers are adding coin-mining scripts into fake tech support websites, and some banking Trojans have added coin-mining behavior to their bags of tricks.

Source link

attempt CoinMining Massive Million PCs Targets
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Arcium reaches 1 million confidential transactions, ZINC ranks third in Solana fee revenue

June 13, 2026

What The FIFA World Cup 2026 Means For Fraud

June 12, 2026

Ethereum Nears 200 Million Non-Empty Wallets Despite Market Uncertainty

June 11, 2026

New SilabRAT Trojan Hijacks Sessions to Steal Crypto

June 10, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Solana (SOL) Drops Into Bearish Zone, Key Supports Come Under Threat

May 20, 2026

DMND Pool Now Open To All Miners, With SOC 2 Compliance and Stratum V2 Support

November 29, 2025

Curve Finance’s new L2 pools fail to boost TVL: Here’s why

September 2, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Elon Musk battles Grok safety claims before SpaceX debut

June 13, 2026

How $48 mln vanished from Tron to Monero before Tether could stop it

June 13, 2026

Goldman Sachs Sees Fed Delaying Rate Cuts This Year – Here’s When the Next One Is Coming

June 13, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$63,870.000.18%
  • ethereumEthereum(ETH)$1,676.470.17%
  • tetherTether(USDT)$1.000.06%
  • binancecoinBNB(BNB)$605.86-0.15%
  • usd-coinUSDC(USDC)$1.000.01%
  • rippleXRP(XRP)$1.150.52%
  • solanaSolana(SOL)$67.771.26%
  • tronTRON(TRX)$0.3166011.48%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.030.07%
  • dogecoinDogecoin(DOGE)$0.0877901.24%