Monero mining malware hidden inside popular game torrents

Source Cryptopolitan

Hackers launched a mass infection campaign to distribute a Monero mining program that could be activated remotely. The hackers delivered the mining payload via popular game torrents and primarily targeted gamers, as gaming PCs commonly tend to have stronger processors with more than 8 cores.

According to a recent report by Kaspersky, hackers launched a mass infection campaign of popular game torrents like Garry’s Mod, Dyson Sphere Program, and Universe Sandbox to distribute Monero mining application. The hackers could activate this application remotely.

Monero mining malware hidden inside popular game torrents
Pie-chart showing the distribution of affected users by game (Source: Kaspersky)

Popular sandbox and simulator games were chosen to distribute the mining program, and the hackers specifically picked games requiring minimal disk space.

The hackers delivered the mining payload via a cracked game installer. Often, such cracked installers require users to turn off their anti-virus to install.

The campaign was referred to as StaryDobry, and it took advantage of torrents consisting of compressed files of the games for quicker downloads.

Kaspersky mentioned that the infections were initially detected in January 2025. However, the campaign started much earlier, in December 2024.

In fact, the campaign has been in preparation since September 2024, at the very least, when the initial versions of these games were uploaded. However, this was only the distribution phase.

The Monero mining program targets processors with 8 cores and above

According to Kaspersky, the remote Monero mining program was activated on 31st December. The functionality of the miner ensures that it makes the most out of the processor’s cores. It first checks if the computer has a process with eight cores or more for the highest yields. If the processor has less than 8 cores, the mining program will not be activated.

Due to this use case, the hackers primarily targeted gamers because gaming PCs are usually equipped with faster processors and strong hardware. According to Kaspersky’s data, most of these infections happened in Russia. However, cases have also been registered in Kazakhstan, Brazil, Germany, and Belarus.

As of yet, the team behind this mass infection hasn’t been identified. However, Kaspersky has reasons to believe that a Russian group is behind the malware, as some of its files use the Russian language. Also, a greater number of infections were reported within Russia.

Cryptopolitan Academy: Are You Making These Web3 Resume Mistakes? - Find Out Here

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
US Dollar Index Price Forecast: Tests 106.50 near descending channel's lower boundaryThe US Dollar Index (DXY), which measures the value of the US Dollar (USD) against its six major peers, maintains its ground around 106.50 during the early European hours on Friday.
Author  FXStreet
11 hours ago
The US Dollar Index (DXY), which measures the value of the US Dollar (USD) against its six major peers, maintains its ground around 106.50 during the early European hours on Friday.
placeholder
3 Stocks to Profit From the AI RevolutionArtificial intelligence (AI) has been a leading driver for many tech stocks like Nvidia in recent years. However, as the AI revolution matures, investors may be looking for ideas b
Author  The Motley Fool
11 hours ago
Artificial intelligence (AI) has been a leading driver for many tech stocks like Nvidia in recent years. However, as the AI revolution matures, investors may be looking for ideas b
placeholder
Elon Musk wields Javier Milei’s Chainsaw at CPAC 25 to signal government cutsBillionaire Elon Musk appeared before a conservative crowd outside Washington on Thursday and wielded a red chainsaw gifted to him by Argentina’s president, Javier Milei. He accused the Democrats of “treason.” He addressed the Conservative Political Action Conference, pledging to slash government spending and endorsing an audit of the Federal Reserve.  Musk, now seen as […]
Author  Cryptopolitan
12 hours ago
Billionaire Elon Musk appeared before a conservative crowd outside Washington on Thursday and wielded a red chainsaw gifted to him by Argentina’s president, Javier Milei. He accused the Democrats of “treason.” He addressed the Conservative Political Action Conference, pledging to slash government spending and endorsing an audit of the Federal Reserve.  Musk, now seen as […]
placeholder
Forex Today: Market focus shifts to February PMI dataHere is what you need to know on Friday, February 21: The action in financial markets quiets down on Friday as investors await preliminary February Manufacturing and Services Purchasing Managers' Index (PMI) data from Germany, the Eurozone, the UK and the US.
Author  FXStreet
12 hours ago
Here is what you need to know on Friday, February 21: The action in financial markets quiets down on Friday as investors await preliminary February Manufacturing and Services Purchasing Managers' Index (PMI) data from Germany, the Eurozone, the UK and the US.
placeholder
Dogecoin (DOGE) Flatlines—Is a Breakout or Breakdown Coming?Dogecoin started a fresh decline below the $0.2620 zone against the US Dollar. DOGE is now consolidating and struggling to clear the $0.2550 resistance. DOGE price started a fresh decline below the
Author  NewsBTC
13 hours ago
Dogecoin started a fresh decline below the $0.2620 zone against the US Dollar. DOGE is now consolidating and struggling to clear the $0.2550 resistance. DOGE price started a fresh decline below the
goTop
quote