Visualização de leitura

DOJ Seizes 400 Illegal FIFA World Cup Streaming Domains

Officials from the US Department of Justice seized nearly 400 domains linked to illegal World Cup streams and warned viewers about the risks of malware, phishing, and data theft.

The post DOJ Seizes 400 Illegal FIFA World Cup Streaming Domains appeared first on TechRepublic.

U.S. Seizes Nearly 400 Illegal FIFA World Cup Streaming Domains

Illegal World Cup Streaming Domains

The Illegal World Cup Streaming Domains crackdown has intensified as the U.S. Department of Justice announced the seizure of nearly 400 websites that were illegally broadcasting FIFA World Cup 2026 matches. The enforcement action, launched ahead of the tournament's knockout stage, targets websites accused of violating copyright infringement laws by offering unauthorized live streams of World Cup matches for profit.

According to the Justice Department, the domains were seized under U.S. copyright law as part of Operation Offsides, an international initiative focused on disrupting digital piracy networks linked to the World Cup.

Illegal World Cup Streaming Domains Targeted Under Operation Offsides

Assistant Attorney General A. Tysen Duva of the Justice Department's Criminal Division said the operation was designed to disrupt international networks profiting from the global popularity of the World Cup.

"We have seized hundreds of domains, used to illegally stream World Cup matches for profit, to disrupt the international networks that profit from the global popularity of the World Cup," Duva said.

He added that the Criminal Division will continue efforts to disrupt and, where appropriate, prosecute websites and individuals involved in the illegal activity.

[caption id="attachment_112952" align="aligncenter" width="602"]Illegal World Cup Streaming Domains Banner posted on seized sites[/caption]

The domain seizures are part of Operation Offsides, led by the National Intellectual Property Rights Coordination Center in coordination with HSI, HSI Attaché offices, private sector organizations, and international law enforcement agencies.

Investigation Supported by FIFA and Industry Partners

According to an affidavit filed in the Eastern District of Virginia, investigators found that the seized websites were providing unauthorized real-time streams of FIFA World Cup 2026 matches as they were being officially broadcast.

HSI special agents confirmed that the domains were actively streaming matches without authorization.

Authorities identified the domains with assistance from FIFA, while additional supporting information was provided by beIN Media Group, NBC Universal, the Motion Picture Association's Alliance for Creativity and Entertainment (ACE), Ultimate Fighting Championship (UFC), and Warner Brothers.

FIFA holds the exclusive rights to organize and stage the FIFA World Cup 2026, which is being hosted across cities in the United States, Canada, and Mexico.

Officials Warn of Copyright and Cybersecurity Risks

Director Ivan J. Arvelo of the National Intellectual Property Rights Coordination Center said unauthorized broadcasts violate intellectual property rights and financially benefit criminal organizations.

He said the operation disrupted networks responsible for stealing and distributing copyrighted content while helping ensure fans access matches through legitimate channels.

HSI Washington Field Office Special Agent in Charge Eric Weindorf also warned that illegal streaming sites may expose users to cybersecurity threats.

According to Weindorf, viewers using unauthorized streaming platforms could face malware risks, insecure connections, and the potential compromise of personal and financial information, in addition to the copyright violations committed by the operators of such sites.

International Enforcement Targets Online Piracy Networks

The domain seizure operation was coordinated with international partners through the International Computer Hacking and Intellectual Property (ICHIP) Network.

Authorities targeted servers and domains associated with online piracy in Peru and Bulgaria, which officials identified as known centers of illegal streaming activity. Additional ICHIP-supported enforcement actions took place in Croatia, Romania, Poland, and Colombia after U.S. authorities shared intelligence to help identify domains involved in unauthorized World Cup broadcasts.

The Justice Department said the operation demonstrates ongoing cooperation between domestic and international law enforcement agencies in combating cross-border piracy.

DOJ Continues Cybercrime and IP Enforcement

The Justice Department noted that its Computer Crime and Intellectual Property Section (CCIPS) investigates and prosecutes cybercrime and intellectual property offenses alongside domestic and international partners.

Since 2020, CCIPS has secured the conviction of more than 180 cybercrime and intellectual property offenders and obtained court orders returning more than $350 million in victim funds.

The latest enforcement follows a similar HSI-led operation during the 2022 FIFA World Cup, when authorities seized more than 70 websites involved in unauthorized streaming.

The Justice Department said Operation Offsides will continue to focus on identifying and shutting down websites that facilitate illegal broadcasts while protecting intellectual property during the FIFA World Cup.

ATM Jackpotting Gang Members Sentenced for Ploutus Malware Attacks

ATM jackpotting

Two Venezuelan nationals have been sentenced to 78 months in prison for their role in an ATM jackpotting scheme that used malware to force cash machines across the United States to dispense money illegally. The operation, which authorities say was part of a broader transnational criminal network, involved the deployment of Ploutus malware on ATMs and resulted in losses exceeding $1.5 million.

Carlos Javier Padron, 36, was sentenced after pleading guilty to conspiracy to commit bank burglary and computer fraud. His co-defendant, Oddry Arnoldo Cabrera Torrealba, 37, received the same sentence on June 11 after pleading guilty to identical charges.

Ploutus Malware Used to Trigger Unauthorized Cash Withdrawals

According to court documents, Padron and Torrealba were members of a criminal network responsible for carrying out ATM jackpotting attacks across the United States. Their role involved physically installing a variant of Ploutus malware on targeted ATMs.

Once activated, the malware enabled attackers to send commands directly to the ATM's cash dispensing module, allowing unauthorized withdrawals of currency. Investigators said the malware was also designed to erase traces of its presence, making it more difficult for financial institutions to detect the compromise.

The two men were arrested by the Lincoln Police Department during an ATM jackpotting incident in October 2024.

More Than $1.5 Million Ordered in Restitution

Along with their prison sentences, Padron and Torrealba were jointly ordered to pay $1,537,696 in restitution to the affected financial institutions.

Officials said the investigation uncovered a much larger criminal operation following their arrests. Authorities have since indicted 96 additional individuals connected to the conspiracy on charges including bank burglary conspiracy, money laundering, computer fraud, unauthorized access to protected computers, bank fraud, and providing material support to a designated foreign terrorist organization.

Authorities Link Scheme to Tren de Aragua

U.S. officials stated that the investigation established direct and indirect links between several indicted co-conspirators and Tren de Aragua, a transnational criminal organization that originated in Venezuela.

According to investigators, the group has expanded its operations throughout the Western Hemisphere and has been involved in crimes including drug trafficking, firearms trafficking, kidnapping, robbery, extortion, commercial sex trafficking, and financial fraud.

Authorities allege that ATM jackpotting became one of the organization's revenue-generating activities, targeting financial institutions across the United States through coordinated cyber-enabled attacks.

Justice Department Says Financial Crimes Fund Organized Crime

Assistant Attorney General A. Tysen Duva said the defendants helped deploy malware as part of a criminal network that stole millions of dollars from ATMs across the country. He added that disrupting such operations is critical to protecting financial institutions from technology-enabled fraud.

U.S. Attorney Lesley Woods for the District of Nebraska described ATM jackpotting as a significant revenue source used to finance the criminal activities attributed to the organization and said federal prosecutors would continue targeting its financial networks.

The FBI's Omaha Field Office said it continues to adapt its investigative efforts as criminal organizations increasingly rely on cyber-enabled financial crimes. Homeland Security Investigations also stated that the prosecution was intended to protect both consumers and the U.S. financial system from organized criminal activity.

Multi-Agency Investigation Continues

The investigation was led by the FBI Omaha Field Office and Homeland Security Investigations, with assistance from numerous federal, state, and local law enforcement agencies across the United States.

The case is being prosecuted by the Justice Department's Computer Crime and Intellectual Property Section, the U.S. Attorney's Office for the District of Nebraska, and Joint Task Force Vulcan.

Officials said the case forms part of a broader federal effort targeting transnational criminal organizations involved in cybercrime, financial fraud, and other organized criminal activities. The investigation into the wider network remains ongoing.

Conti Ransomware Conspirator Pleads Guilty in $150M Scheme

Conti ransomware

A Ukrainian national has pleaded guilty to his role in the Conti ransomware operation, one of the most prolific cybercrime campaigns in recent years. The U.S. Department of Justice announced that Oleksii Oleksiyovych Lytvynenko, 44, admitted to participating in a conspiracy that deployed Conti ransomware against more than 1,000 victims worldwide, resulting in at least $150 million in ransom payments. Lytvynenko entered his guilty plea after being extradited from Ireland to the United States. He pleaded guilty to participating in a wire fraud conspiracy connected to the ransomware scheme that targeted organizations across the United States and dozens of other countries.

Conti Ransomware Targeted Victims Worldwide

According to court documents, the Conti ransomware group carried out attacks between 2020 and 2022, compromising computers and networks in 47 U.S. states, the District of Columbia, Puerto Rico, and 31 foreign countries. Investigators allege that members of the operation gained unauthorized access to victim networks, encrypted critical data, and demanded ransom payments in exchange for restoring access. Victims were also threatened with public exposure of stolen information if they refused to pay. The FBI estimates that, by January 2022, the ransomware campaign had generated at least $150 million in ransom proceeds, making Conti one of the most financially damaging ransomware operations ever investigated by U.S. authorities. Assistant Attorney General A. Tysen Duva said the defendants used the ransomware variant to terrorize businesses and individuals globally, causing extensive financial losses and operational disruption.

Defendant Admitted Role in Malware Development

Court filings show that Lytvynenko joined the conspiracy no later than September 2021. He admitted to possessing stolen data belonging to eight U.S. victims and four international victims whose information had been compromised by members of the group. Authorities also stated that he worked as part of a team directed by another Conti conspirator and assisted in developing a malware "loader." Such tools are commonly used to deploy malicious software and execute additional attacks on compromised systems. The admission provides investigators with further insight into the technical infrastructure behind the Conti ransomware operation and the roles played by individual members within the criminal enterprise.

International Cooperation Led to Arrest and Extradition

The case highlights the growing collaboration between international law enforcement agencies in combating cybercrime. U.S. authorities worked alongside multiple Irish agencies, including the Irish Department of Justice, Home Affairs and Migration, the Office of the Attorney General, and the Garda National Cyber Crime Bureau to secure Lytvynenko's arrest and extradition. Assistant Director Brett Leatherman of the FBI Cyber Division described the guilty plea as an important step toward holding cybercriminals accountable for the damage caused to victims around the world. The U.S. Secret Service also emphasized that international borders would not prevent authorities from pursuing individuals involved in ransomware operations. Officials said the case demonstrates a continued commitment to identifying and prosecuting every member of organized cybercriminal networks.

Part of Broader Operation Riptide Crackdown

The prosecution forms part of Operation Riptide, an ongoing FBI initiative targeting criminal actors, infrastructure, and financial networks involved in cyber-enabled crime and fraud. According to the Department of Justice, Americans reported more than $20 billion in cybercrime-related losses last year, representing a 26% increase from the previous year. Through Operation Riptide, authorities are focusing on dismantling ransomware groups, fraud operations, and other transnational cybercriminal organizations responsible for significant financial harm. Lytvynenko faces a maximum sentence of 20 years in federal prison. He is scheduled to be sentenced on September 10, 2026. A federal judge will determine the final sentence after considering federal sentencing guidelines and other statutory factors. The investigation was led by the FBI's San Diego, Nashville, and El Paso field offices, alongside the U.S. Secret Service. Prosecutors noted that the case remains part of a broader effort to identify and prosecute additional individuals linked to the Conti ransomware conspiracy.

Pirated PC games are delivering password-stealing malware

A new Windows malware campaign hides inside pirated PC games and modified installers for franchises like Far Cry, Need for Speed, FIFA, and Assassin’s Creed.

Researchers estimate that more than 400,000 devices worldwide have been infected, with around 30,000 users in the US.

The infection method is simple and effective. Users are lured into installing a fully functional free game. While the cracked and repacked game appears to work, the malware installs silently in the background.

The strain is being called “RenEngine loader” and sometimes referred to as Ren’Py because parts of the malicious code are embedded in a legitimate Ren’Py launcher used to run some visual novel games. When the launcher runs, it decompresses the game files and secretly starts the infection chain.

Ren’Py is a legitimate, open-source visual novel engine used by developers to make story-driven games with text, images, sound, and interactive choices. The malware in this case is not Ren’Py itself. Attackers are abusing the engine or its launcher as a delivery method to hide malicious code inside pirated game installs.

In practice, the primary infection vector is software piracy. Victims download cracked games or repacked installers from unofficial sites, then run what looks like a normal game launcher or setup file. In reality, they’re infecting their computer with a malware loader.

At the time of writing, this loader is trying to deliver an infostealer called ARC, which can grab saved browser passwords, cookies, cryptocurrency wallets, autofill data, system details, and clipboard contents.

But we’ve also seen other payloads being dropped, including Rhadamanthys stealer, Async Remote Access Trojan (RAT), and Backdoor.XWorm, which can expand the damage from credential theft to full remote control of the machine. That can mean account takeovers, financial fraud, crypto theft, and deeper compromise of personal or work data.

Worst of all, a user may not realize they are infected until usernames and passwords have been stolen or the machine starts behaving strangely. 

How to stay safe

The most important lesson here is that “free” cracked software is often a delivery mechanism for malware, not a bargain. Once a loader like this is on the machine, the real goal is usually to steal credentials or install a secondary payload that is more persistent and more damaging.

Some other general advice to stay safe:

  • Don’t download installers from unofficial sources.
  • Use real-time, up-to-date anti-malware protection to block loaders.
  • Keep your software up to date, especially Microsoft patches and other security-related programs.

If you think your computer is infected and want to make sure, follow the instructions posted here. The amazing volunteers on our forums will help you through the process of cleaning your machine.


We don’t just report on threats—we remove them

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Pirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for years

Introduction

In late April 2026, a client reached out to us for incident response support after discovering a miner running on users’ computers. We later discovered that the malware was being distributed via illegal movie and TV show streaming sites. The infection chain leveraged a fake update for a video player plugin. When the user attempted to watch a video, the player displayed a message saying the plugin version was outdated and asking to install an update to continue.

Clicking the link downloaded a ZIP archive with the following contents:

The archive contained a legitimate executable, HLS Installer.874.exe, alongside a malicious DLL. Launching the EXE triggered a DLL side-loading mechanism, injecting the malicious module into a legitimate program process and executing code within its context. The library contained the logic for deploying the miner and establishing persistence on the device.

At the time of the investigation, the infection risk was associated with two pirated video sites in the .ru and .top TLDs.

Link to previous campaigns

The current incident does not appear to be an isolated case. After analyzing the infection vector and the logic of the DLL, we concluded that this activity is a continuation of a campaign involving pirated digital libraries, which was previously described by another cybersecurity company.

The delivery mechanism for the malicious archive has remained virtually unchanged. Previously, the archive was downloaded in parts from the domain file[.]ipfs[.]us[.]69[.]mu, but this domain was unavailable at the time of our investigation. Instead, the threat actor employed a new website, urush1bar4[.]online.

The structure of the archive has also been preserved: inside is a legitimate executable and a large malicious DLL (see the screenshot below).

In the course of our research, we also discovered a blog post by NTT Security describing a similar delivery method for a malicious archive. In that instance, the threat actors displayed a fake browser crash page (shown below) while simultaneously downloading an archive to the device with a name starting with chromium-patch-nightly.

This scenario resembles the current scheme involving the fake video player plugin update. Given the previously described activity, it’s safe to assume that this campaign has been active since at least 2022. Throughout this entire period, the threat actor has been updating both the downloadable malware and individual parts of the infection mechanism.

Potential distribution scale

As in previous episodes of the campaign, infections occur via highly popular websites. As of late April 2026, sites linked to the campaign typically displayed extremely high monthly traffic. For instance, the audience for the smallest of the free digital libraries stood at 11,000 users, while the largest reached 4.7 million. For pirated movie and TV show streaming sites, this figure ranged from 2.1 million to 27.4 million. In April, the total number of visits to websites where the malware described in this study was detected reached 40 million.

The popularity of these sites increases the potential scale of the miner’s distribution. Furthermore, the campaign is not limited to a single type of platform: the malicious archive is being distributed through both online digital libraries and movie and TV show streaming sites. This broadens the potential range of victims and makes it more difficult to attribute the threat to a single infection vector.

The downloadable archive

The current version of the downloadable malware is a ZIP archive containing a legitimate EXE file and a malicious DLL. When the executable runs, the library side-loads into its process, triggering the malicious logic.

The technical analysis that follows covers the current version of this malware. This version was first observed in April 2025 and has been distributed unmodified for over a year.

DLL analysis

Most of the data inside the DLL carries no meaningful weight and was randomly generated just to inflate the file size and impede analysis.

Amidst the large volume of junk code inside the DLL, there is a single function that triggers a stack overflow during execution:

Based on the code, the size of the stackBuf buffer on the stack is only 64 bytes, and the SmashStack function overwrites this buffer without validating the length of the input data.

This overflow constructs a ROP chain that decrypts the next stage. After decryption, it transfers execution to code located within the modified DOS header of the PE file:

The header was intentionally modified to make it into valid shellcode:

pop     r10
push    r10
call    $+5
pop     rcx 
sub     rcx, 9
mov     rax, rcx
add     rax, 5C1000h
call    rax
retn

This shellcode passes control to a function located at offset 0x5C1000 from the base of the PE file. This function then reflectively loads the same PE file into memory.

Going forward, we will refer to this decrypted PE file as the main module.

Main module

The module’s behavior across its different operational stages is detailed below:

The main module is a modified fork of the SilentCryptoMiner project. We have previously analyzed miners leveraging this project in other posts: Scam Information and Event Management and Undercover miner: how YouTubers get pressed into distributing SilentCryptoMiner as a restriction bypass tool. However, this specific fork has not been documented anywhere before, which is why we decided to break down its unique features in detail in this article.

Upon an initial run, the main module checks whether it has permission to proceed with execution. To do this, it collects the following data from the victim’s device:

  • Processor information
  • The serial number of the C:/ drive
  • Whether the process was launched with elevated privileges
  • The process start time in Unix timestamp format

The information is transmitted as a single large DNS query using the DNS tunneling technique. An example of the DNS query is shown below:

The attackers disguise the DNS query as legitimate traffic through low-level packet crafting and by using a domain name ending in microsoft.com. However, the IP address to which the query is actually sent has no relation to Microsoft.

DNS query crafting code

DNS query crafting code

The execution of the main module proceeds only if the following byte sequence is detected in the response: 01 02 03 04. Following a successful check, the main module launches, and the subsequent logic is adjusted depending on whether the process has elevated privileges on the compromised host.
Let’s look at both scenarios:

1. The process is launched with elevated privileges.

In this case, preparatory steps precede the miner launch:

  • The malware adds Windows Defender exclusions for EXE and DLL files, as well as for the %USERPROFILE%, %PROGRAMDATA%, and %WINDIR% folders.
  • It kills Microsoft’s Malicious Software Removal Tool (MSRT) by calling ZwSetInformationFile with the FileDispositionInformation type, which causes the mrt.exe file to be deleted upon closing. To prevent MSRT from being automatically installed during the next update, the DontOfferThroughWUAU parameter is created with a value of 1 under the HKLM\Software\Policies\Microsoft\MRT registry key.
  • Automatic hibernation and sleep mode are disabled for when the device is running on both AC power and battery.

powercfg /x -hibernate-timeout-ac 0
powercfg /x -hibernate-timeout-dc 0
powercfg /x -standby-timeout-ac 0
powercfg /x -standby-timeout-dc 0

This is done to maximize the miner’s potential runtime on the device.

Next, to achieve persistence, a copy is created in the C:\ProgramData\Google\Chrome directory, after which the GoogleUpdateTaskMachineQC service is registered and configured to launch automatically at system startup.

Finally, four reflexive loads are executed: the components are injected directly into the memory of the target processes without writing to disk, having bypassed standard Windows loading mechanisms. Each implant is injected into its own host process:

  • RAT agent → into conhost.exe
  • Watchdog → into explorer.exe
  • CPU miner → into explorer.exe
  • GPU miner → into explorer.exe, but only if a discrete GPU is present in the system. This is verified by enumerating all display adapters in the system.

2. The process is launched with standard privileges.

In this scenario, the miner begins repeatedly triggering User Account Control (UAC) prompts until it is successfully executed with elevated privileges. The workflow is as follows:

  1. Upon initial execution, a copy is made to the %USERPROFILE%\AppData\Roaming\Sandboxie directory and relaunched from there. Simultaneously, an attempt is made to launch it with elevated privileges via UAC.
  2. If execution occurs from the Sandboxie folder:
  • Persistence is configured for the miner copy in this folder by adding an entry to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run.
  • Every three minutes, an attempt is made to launch with elevated privileges via UAC until the GoogleUpdateTaskMachineQC service is successfully installed.

A successful installation requires all of the following conditions to be met:

  1. The GoogleUpdateTaskMachineQC service exists in the system.
  2. The Start value for this service is set to 2 (Automatic).
  3. The ImagePath value points to a file in the C:\ProgramData\Google\Chrome folder.
  4. This file exists on disk.

Watchdog

The purpose of this component is to ensure the uninterrupted operation of the miner. At the very beginning of its execution, it copies all files from the C:\ProgramData\Google\Chrome folder and encrypts the contents of each file using a cyclic XOR algorithm with the key AFeIboiOmImJS2ypJU0pTpAO61SELkUc. After that, the encrypted contents are written into the process memory, and the following structure is created in memory for each file:

class FileContainer{
	wchar_t* fullPath; // full path to file
	size_t* ptrSize;   // pointer to file size
	uint8_t* xorEncryptedFile; //pointer to buffer containing encrypted file contents
};

As soon as the contents of all files are saved in memory, Watchdog enters an infinite loop, where every five seconds, it checks the integrity of the installed GoogleUpdateTaskMachineQC service, just as the main module does. If the service is found to be incorrectly installed, the miner overwrites its files in the C:\ProgramData\Google\Chrome path with the contents acquired at startup.

To successfully remediate the miner, this module, which runs inside the explorer.exe process, must be terminated first.

RAT agent

This module provides remote control capabilities via four commands, which are described at the end of this section. The command-and-control addresses used to receive these commands follow this format:

  • http://{domain}.space/index.php?authorization=1
  • http://{domain}.site/index.php? backup version

The {domain} is calculated based on the current date. The process starts with the current year, then adds the zone identifier for the current month. All 12 months are divided into four zones. Finally, the word microsoft is appended to the resulting string. This final string is used as the input for subsequent double hashing using the MurmurHash64 algorithm. The hash output is the domain for the implant to communicate with.

At the time of writing this, the following domains were registered:

  • 2025, April-July → 5d14vnfb[.]space
  • 2025, August-November → r7mvjl67[.]space
  • 2025, December → zgj1tam9[.]space
  • 2026, January-March → jeaw520i[.]space
  • 2026, April–July → qdmagva5[.]space

An example of a request to the C2 server is provided below:

As can be seen, the request contains an encrypted body consisting of data encrypted via AES-CBC with the key 0123456789abcdef0123456789abcdef and the initialization vector 000102030405060708090a0b0c0d0e0f. The data contains a list of installed programs on the system, along with processor information and the serial number of the C: drive.

This information is likely used by the backend to check for virtual or debugging environments.

The first 16 bytes of the server response body represent the initialization vector for the AES-CBC algorithm with the key 0123456789abcdef0123456789abcdef, while the remaining bytes are the data encrypted with this algorithm. The decrypted data contains a malicious payload, as well as its RSA-SHA256 signature (sign):

struct PLAINTEXT{ 
uint32_t len_payload; 
uint8_t payload[len_payload]; 
uint32_t len_sign; 
uint8_t sign[len_signature]; 
}

The authenticity of the message is verified via the sign signature using the server’s public key, which is embedded in the executable.

Inside the malicious payload is a 4-byte code that determines the subsequent behavior of the program, along with additional data whose meaning depends on the code.

The table below lists the four remote control commands for the RAT agent module.

Code Purpose
1 Execution of an arbitrary command
2 Reflexive execution of the provided PE file within the explorer.exe process
3 Execution of the provided shellcode
4 Exit

The miners

Depending on whether a discrete GPU is present in the system, either the CPU miner alone or a combination of the CPU and GPU miners is launched. The CPU miner is based on XMRig, while the GPU miner supports multiple algorithms.

Upon initial execution, both miners attempt to retrieve their startup configuration from a remote server. The potential addresses are listed below:

  • “{domain}.strangled.net”
  • “{domain}.ignorelist.com”
  • “{domain}.ftp.sh”
  • “{domain}.zanity.net”

As with the RAT agent component, the server address is generated from the current date — in this case, the server address changes every week. This results in quite a large number of domains for the 2020–2030 period; however, all of them point to the same IP address: 107[.]172[.]212[.]235. The first available domain out of the four potential domains listed above will be used.

The algorithm for retrieving the configuration from the server is completely identical to that used by the RAT agent, with the sole exception that th1s1sth3key0f4n1ntere5t1ngw0rld is used as the AES-CBC key in this scenario, and the configuration resides within the payload. The retrieved configuration is encrypted via AES-CBC using the key UXUUXUUXUUCommandULineUUXUUXUUXU and the initialization vector UUCommandULineUU. The encrypted data is then converted into a base64 string, which is passed as a command-line parameter to launch the miner inside the explorer.exe process through process hollowing.

Conclusion

Our investigation focused on an ongoing campaign distributing miners via popular illegal content sites. The threat actors leverage a variety of sites, ranging from online libraries to movie and TV show streaming platforms. There is no telling what channels they will use to distribute the malicious archive in the future. However, the current case shows that users visiting pirated websites continue to take a serious risk.

Our products detect this malware with the following Generic verdicts:

  • HEUR:Trojan.Win64.DllHijack.gen
  • MEM:Trojan.Win32.SEPEH.gen

Indicators of Compromise

Malicious archive download URL
urush1bar4[.]online

Malicious DLL libraries:
6A0FE6065D76715FEEBC1526D456DB73
7F624407AE489324E96A708A09C17E6F
02A43B3423367B9DDDC24CC7DFC070DF

RAT C&C:
5d14vnfb[.]space
r7mvjl67[.]space
zgj1tam9[.]space
jeaw520i[.]space
qdmagva5[.]space

Configuration retrieval address
107[.]172[.]212[.]235

UnamWebPanel control panel addresses
m4yuri[.]online
kristina[.]quest

❌