According to Kaspersky, the campaign launched last December and targets users who are downloading torrents of popular games with silent installations of Xmrig, the Monero Mining program.
Crypto Malware Target Gamers: MoneroMining Payloads Delivered via Popular Game Torrents
Hackers are currently targeting gamers with competent computers with cryptographic malware. According to Russian cybersecurity company Kaspersky, Crypto Criminals has begun using torrents from popular games such as Beamng.Drive, Garry’s Mod, Dyson Sphere Program, Universe Sandbox and Pulutocracy.
Mining payloads are delivered via crack installers that avoid copy security systems and allow users to install and play downloaded games. The campaign is derived from “Starrydobry,” which utilizes a compressed instance of the game that allows you to download these cracked versions faster, using the so-called repack torrent distribution.
Kaspersky said it began detecting these infections in January 2025. Still, the company’s research shows that the campaign has been in preparation since at least September when the first versions of these game releases were uploaded.
However, this was just a distribution stage as instances of Xmrig, the Monero Mining Program, were remotely activated from December 31st when it detected the first large-scale infection.
Minor checks if the computer that is installed first has a processor with 8 or more cores. These are because they provide the attacker with the highest yield. If your installer has a computer with less than 8 cores processors, Monero Miner will not be active due to poor performance.
This use case describes the detected attack vectors, as game rigs are usually made up of powerful hardware to enjoy better performance in gaming tasks. Kaspersky revealed that most of the infections occurred in Russia, with additional cases registered in Belarus, Kazakhstan, Germany and Brazil.
The team behind this campaign has not been identified, but Kaspersky could be a Russian group given the use of Russian parts and the scale of Russian infections. I think so.
Read more: ledger users targeting new data breach phishing campaigns
Discover more from Earlybirds Invest
Subscribe to get the latest posts sent to your email.