A new cyber-attack campaign is targeting consumers and small to medium-sized businesses globally, aiming to steal cryptocurrency data and mine Monero. The campaign, first observed in April 2026 by Unit 42, the research division of Palo Alto Networks, employs a dual monetization strategy.
Attackers initially lure victims through malicious advertisements that direct them to pages offering what appear to be cracked versions of copyrighted software. These download pages mimic legitimate services, such as the German streaming guide JustWatch GmbH, or present certificates resembling those from BleacherReport[.]com. Researchers clarified that JustWatch itself has not been compromised.
The malicious files are distributed within password-protected archives, often using a .bin extension in the filename. This method is designed to evade detection by email gateway scanners and prevent automated analysis in sandboxed environments, as the password is required for extraction.
To further hinder security software, the attackers have implemented anti-analysis techniques. These include process enumeration and an AMSI (Antimalware Scan Interface) bypass, where the AmsiScanBuffer function is modified to evade detection by certain security tools.
Once executed, the loader component deploys both the Vidar infostealer and the XMRig cryptocurrency miner. Vidar is designed to extract sensitive information from a victim's system, including browser credentials, session cookies, and cryptocurrency wallet details. Concurrently, XMRig utilizes the compromised computer's processing power to mine Monero by solving complex mathematical problems essential for verifying network transactions and securing the blockchain.
The operators behind this campaign profit from both stolen data and hijacked computing resources. Credentials and session cookies acquired by Vidar are sold on illicit marketplaces, while the Monero mining operation provides a steady, passive income stream derived from the victim's CPU cycles.
Analysis of 99 loader samples revealed that the attackers utilized the Factory-v3 framework, a known malware-as-a-service (MaaS) builder used for creating various types of stealer malware. This framework appears to be an independent service supporting at least two distinct infostealer affiliate groups.
Command-and-control (C2) communications for this campaign were observed being managed through Telegram. A specific tag, "X3D MINER," was present in Telegram notifications sent by the operator for each new victim infection. This behavior has previously been linked to a known threat group that has been observed distributing XMRig and bundling it with other malicious programs.






