Close Menu
Chain Tech Daily

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Academic Grants Round grantee announcement

    September 5, 2025

    Justin Sun plans to invest $20m in WLFI and ALTS

    September 5, 2025

    Bitcoin treasury firm NAKA’s shares and mNAV crashed 90%

    September 5, 2025
    Facebook X (Twitter) Instagram
    Chain Tech Daily
    • Altcoins
      • Litecoin
      • Coinbase
      • Crypto
      • Blockchain
    • Bitcoin
    • Ethereum
    • Lithosphere News Releases
    Facebook X (Twitter) Instagram YouTube
    Chain Tech Daily
    Home » Darktrace flags new cryptojacking campaign able to bypass Windows Defender
    Crypto

    Darktrace flags new cryptojacking campaign able to bypass Windows Defender

    James WilsonBy James WilsonSeptember 3, 20253 Mins Read
    Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Cybersecurity firm Darktrace has identified a new cryptojacking campaign designed to bypass Windows Defender and deploy a crypto mining software.

    Summary

    • Darktrace has identified a cryptojacking campaign that targets Windows systems.
    • The campaign involves stealthily deploying the NBminer to mine cryptocurrencies.

    The cryptojacking campaign, first identified in late July, involves a multi-stage infection chain that quietly hijacks a computer’s processing power to mine cryptocurrency, Darktrace researchers Keanna Grelicha and Tara Gould explained in a report shared with crypto.news.

    According to the researchers, the campaign specifically targets Windows-based systems by exploiting PowerShell, Microsoft’s built-in command-line shell and scripting language, through which bad actors are able to run malicious scripts and gain privileged access to the host system.

    These malicious scripts are designed to run directly on system memory (RAM) and, as a result, traditional antivirus tools that typically rely on scanning files on a system’s hard drives are unable to detect the malicious process.

    Subsequently, attackers use the AutoIt programming language, which is a Windows tool typically used by IT professionals to automate tasks, to inject a malicious loader into a legitimate Windows process, which then downloads and executes a cryptocurrency mining program without leaving obvious traces on the system.

    As an added line of defense, the loader is programmed to perform a series of environment checks, such as scanning for signs of a sandbox environment and inspecting the host for installed antivirus products.

    Execution only proceeds if Windows Defender is the sole active protection. Further, if the infected user account lacks administrative privileges, the program attempts a User Account Control bypass to gain elevated access.

    When these conditions are met, the program downloads and executes the NBMiner, a well-known crypto mining tool that uses a computer’s graphics processing unit to mine cryptocurrencies such as Ravencoin (RVN) and Monero (XMR).

    In this instance, Darktrace was able to contain the attack using its Autonomous Response system by “preventing  the device from making outbound connections and blocking specific connections to suspicious endpoints.”

    “As cryptocurrency continues to grow in popularity, as seen with the ongoing high valuation of the global cryptocurrency market capitalization (almost USD 4 trillion at time of writing), threat actors will continue to view cryptomining as a profitable venture,” Darktrace researchers wrote.

    Back in July, Darktrace flagged a separate campaign where bad actors were using complex social engineering tactics, such as impersonating real companies, to trick users into downloading altered software that deploys crypto-stealing malware.

    Unlike the aforementioned cryptojacking scheme, this approach targeted both Windows and macOS systems and was executed by unaware victims themselves who believed they were interacting with company insiders. 



    Source link

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
    James Wilson

    Related Posts

    Crypto September 5, 2025

    Justin Sun plans to invest $20m in WLFI and ALTS

    Crypto September 5, 2025

    SEC and CFTC push for regulatory clarity on DeFi, on-chain finance

    Crypto September 5, 2025

    Chinese fintech eyes Venom blockchain in push for digital finance modernization

    Crypto September 5, 2025

    Can $0.18 hold after a 60% collapse?

    Crypto September 5, 2025

    Ethereum price may rally amid shrinking Binance supply

    Crypto September 5, 2025

    SEC postpones decision on 21Shares SUI ETF

    Leave A Reply Cancel Reply

    Don't Miss
    Ethereum September 5, 2025

    Academic Grants Round grantee announcement

    We are thrilled to announce the 39 grantees selected for the recent Academic Grants Round.…

    Justin Sun plans to invest $20m in WLFI and ALTS

    September 5, 2025

    Bitcoin treasury firm NAKA’s shares and mNAV crashed 90%

    September 5, 2025

    Nasdaq files 19b-4 form for ‘Canary Litecoin ETF’ SEC approval

    September 5, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • YouTube
    • LinkedIn
    Our Picks

    Academic Grants Round grantee announcement

    September 5, 2025

    Justin Sun plans to invest $20m in WLFI and ALTS

    September 5, 2025

    Bitcoin treasury firm NAKA’s shares and mNAV crashed 90%

    September 5, 2025

    Nasdaq files 19b-4 form for ‘Canary Litecoin ETF’ SEC approval

    September 5, 2025

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Don't Miss
    Ethereum September 5, 2025

    Academic Grants Round grantee announcement

    We are thrilled to announce the 39 grantees selected for the recent Academic Grants Round.…

    Justin Sun plans to invest $20m in WLFI and ALTS

    September 5, 2025

    Bitcoin treasury firm NAKA’s shares and mNAV crashed 90%

    September 5, 2025

    Nasdaq files 19b-4 form for ‘Canary Litecoin ETF’ SEC approval

    September 5, 2025

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    About Us
    About Us

    ChainTechDaily.xyz delivers the latest updates and trends in the world of cryptocurrency. Stay informed with daily news, insights, and analysis tailored for crypto enthusiasts.

    Our Picks
    Lithosphere News Releases

    Imagen Network (IMAGE) Adds XRP Ledger Support to Improve Blockchain Interoperability

    September 5, 2025

    Imagen Network (IMAGE) Developer Presents Plan to Buy $150M in Ethereum (ETH)

    September 4, 2025

    Imagen Network (IMAGE) Integrates Grok Intelligence to Expand Adaptive Creator Engagement

    September 2, 2025

    Imagen Network (IMAGE) Integrates Grok Models to Advance Creator Personalization

    August 29, 2025
    X (Twitter) Instagram YouTube LinkedIn
    © 2025 Copyright

    Type above and press Enter to search. Press Esc to cancel.