- A crypto miner disguised as a tool to bypass Internet restrictions has reportedly infected hundreds of thousands of Russian users.
Cybersecurity experts and the authorities have linked many cryptocurrency theft cases to malware attacks. These activities allow bad actors to access the victim’s private keys and digital wallets, resulting in financial losses. The largest heist by far that employed a malicious code to steal data and resources was the Bybit hack, which resulted in the loss of $1.5 million worth of Ethereum (ETH) assets.
Recently, Kaspersky researchers sounded the alarm on a new malware plaguing Russian users. The malicious program SilentCryptoMiner masks itself as a tool to circumvent Internet restrictions.
In reality, it serves as a crypto mining tool capable of mining several cryptocurrencies. As a stealthy program, it uses considerable computational power for its mining activities, resulting in increased operational costs, damage, or security gaps within the unsuspecting victim’s rig.
SilentCryptoMiner’s Features
The cybersecurity firm discovered the malware in October 2024. They found the campaign while analyzing cyber criminals’ increased use of Windows Packet Divert (WPD) tools to distribute malware. According to them, the stealthy miner was based on the open-source mining tool XMRig.
SilentCryptoMiner is capable of mining Ethereum, Ethereum Classic (ETC), Monero (XMR), and Raptoreum (RTM), among others. It avoids detection by halting operations whenever the target computing device runs specific monitoring tools. Then, it fetches updates from the system every 100 minutes.
How the Stealthy Crypto Miner Spreads
Cybersecurity site Security Affairs traced the distribution of the malware via an infected archive in a malicious site called “gitrok.com.” Upon checking, it has already amassed 40,000 downloads.
However, the proliferation of the crypto miner in question was significantly boosted via YouTube. The sources claimed that the malware’s developers and distributors have been manipulating YouTubers under the pretense of copyright strikes. From there, they try to arrive at a compromise with the unsuspecting intermediary of their dubious activities that they will not pursue the channel’s shutdown if the YouTuber posted a video containing a link.
The perpetrators also employed social engineering tactics via the social messaging app Telegram. Experts tracked the spread of the malicious software from over 340,000 subscribers of popular YouTube and Telegram channels.
The malware contains a modified script that tricks victims into disabling their antivirus protocols. It starts with a Python-based loader packaged with PyInstaller, which is usually obfuscated using PyArmor. After that, it sources a second-stage payload from hardcoded domains, which it executes as t.py under a temporary folder.
Interestingly, the investigators detected that the payload was only accessible through Russian IP (Internet Protocol) addresses. This indicates that it particularly targets Russian users.
Kaspersky advises everyone to avoid downloading programs from questionable or little-known sources. On the other hand, even official platforms and reputable vloggers do not guarantee 100% security. Hence, it recommends the use of reliable protection for their devices, such as antivirus tools.







