Darktrace cryptoDarktrace crypto

Darktrace flags new cryptojacking campaign able to bypass Windows Defender

Cybersecurity firm Darktrace has identified a new cryptojacking campaign designed to bypass Windows Defender and deploy a crypto mining software.

Summary
  • Darktrace has identified a cryptojacking campaign that targets Windows systems.
  • The campaign involves stealthily deploying the NBminer to mine cryptocurrencies.

The cryptojacking campaign, first identified in late July, involves a multi-stage infection chain that quietly hijacks a computer’s processing power to mine cryptocurrency, Darktrace researchers Keanna Grelicha and Tara Gould explained in a report shared with crypto.news.

According to the researchers, the campaign specifically targets Windows-based systems by exploiting PowerShell, Microsoft’s built-in command-line shell and scripting language, through which bad actors are able to run malicious scripts and gain privileged access to the host system.

These malicious scripts are designed to run directly on system memory (RAM) and, as a result, traditional antivirus tools that typically rely on scanning files on a system’s hard drives are unable to detect the malicious process.

Subsequently, attackers use the AutoIt programming language, which is a Windows tool typically used by IT professionals to automate tasks, to inject a malicious loader into a legitimate Windows process, which then downloads and executes a cryptocurrency mining program without leaving obvious traces on the system.

As an added line of defense, the loader is programmed to perform a series of environment checks, such as scanning for signs of a sandbox environment and inspecting the host for installed antivirus products.

Execution only proceeds if Windows Defender is the sole active protection. Further, if the infected user account lacks administrative privileges, the program attempts a User Account Control bypass to gain elevated access.

When these conditions are met, the program downloads and executes the NBMiner, a well-known crypto mining tool that uses a computer’s graphics processing unit to mine cryptocurrencies such as Ravencoin (RVN) and Monero (XMR).

In this instance, Darktrace was able to contain the attack using its Autonomous Response system by “preventing  the device from making outbound connections and blocking specific connections to suspicious endpoints.”

“As cryptocurrency continues to grow in popularity, as seen with the ongoing high valuation of the global cryptocurrency market capitalization (almost USD 4 trillion at time of writing), threat actors will continue to view cryptomining as a profitable venture,” Darktrace researchers wrote.

Cryptojacking campaigns via social engineering

Back in July, Darktrace flagged a separate campaign where bad actors were using complex social engineering tactics, such as impersonating real companies, to trick users into downloading altered software that deploys crypto-stealing malware.

Unlike the aforementioned cryptojacking scheme, this approach targeted both Windows and macOS systems and was executed by unaware victims themselves who believed they were interacting with company insiders. 

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Japan-Based Bitcoin Treasury Company Metaplanet Completes $1.4 Billion IPO! Will It Buy Bitcoin? Here Are the Details

Japan-Based Bitcoin Treasury Company Metaplanet Completes $1.4 Billion IPO! Will It Buy Bitcoin? Here Are the Details

The post Japan-Based Bitcoin Treasury Company Metaplanet Completes $1.4 Billion IPO! Will It Buy Bitcoin? Here Are the Details appeared on BitcoinEthereumNews.com. Japan-based Bitcoin treasury company Metaplanet announced today that it has successfully completed its public offering process. Metaplanet Grows Bitcoin Treasury with $1.4 Billion IPO The company’s CEO, Simon Gerovich, stated in a post on the X platform that a large number of institutional investors participated in the process. Among the investors, mutual funds, sovereign wealth funds, and hedge funds were notable. According to Gerovich, approximately 100 institutional investors participated in roadshows held prior to the IPO. Ultimately, over 70 investors participated in Metaplanet’s capital raising. Previously disclosed information indicated that the company had raised approximately $1.4 billion through the IPO. This funding will accelerate Metaplanet’s growth plans and, in particular, allow the company to increase its balance sheet Bitcoin holdings. Gerovich emphasized that this step will propel Metaplanet to its next stage of development and strengthen the company’s global Bitcoin strategy. Metaplanet has recently become one of the leading companies in Japan in promoting digital asset adoption. The company has previously stated that it views Bitcoin as a long-term store of value. This large-scale IPO is considered a significant step in not only strengthening Metaplanet’s capital but also consolidating Japan’s role in the global crypto finance market. *This is not investment advice. Follow our Telegram and Twitter account now for exclusive news, analytics and on-chain data! Source: https://en.bitcoinsistemi.com/japan-based-bitcoin-treasury-company-metaplanet-completes-1-4-billion-ipo-will-it-buy-bitcoin-here-are-the-details/
Share
BitcoinEthereumNews2025/09/18 08:42
InvestCapitalWorld Updates Platform Features to Support Broader Multi-Asset Market Access

InvestCapitalWorld Updates Platform Features to Support Broader Multi-Asset Market Access

The post InvestCapitalWorld Updates Platform Features to Support Broader Multi-Asset Market Access appeared on BitcoinEthereumNews.com. Paris, France, January 16th
Share
BitcoinEthereumNews2026/01/16 21:27
Why X Banned Information Finance Apps In 2026

Why X Banned Information Finance Apps In 2026

The post Why X Banned Information Finance Apps In 2026 appeared on BitcoinEthereumNews.com. InfoFi Tokens Crash: Why X Banned Information Finance Apps In 2026 Skip
Share
BitcoinEthereumNews2026/01/16 21:32