A wormable cryptojacking campaign has been reported distributing a custom XMRig miner through pirated “premium” software bundles. The multi-stage infection chain is designed to maximize mining hashrate—often destabilizing infected systems—and includes worm-like propagation to spread via external storage devices, enabling movement even in air-gapped environments.
Technical analysis attributes the campaign to a modular controller binary (commonly referenced as Explorer.exe) that operates as a persistent state machine, switching roles (e.g., installer, watchdog, payload manager, cleaner) based on command-line arguments. The malware uses BYOVD (Bring Your Own Vulnerable Driver) by loading a legitimate signed but vulnerable driver (reported as WinRing0x64.sys) to obtain elevated/kernel-level capabilities, and it incorporates a time-based logic bomb/kill switch that checks local system time against a hard-coded timestamp to gate behavior and support stealthy cleanup/self-destruct routines.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
On February 23, 2026, Trellix disclosed details of the cryptojacking campaign, describing its use of pirated software lures, a modular multi-stage dropper, USB worm propagation, and BYOVD-based privilege escalation. The report also highlighted watchdog components, a controller binary named Explorer.exe, and a kill-switch mechanism dubbed 'Barusu'.
The malware included a logic bomb configured to trigger on December 23, 2025, after which it would perform a controlled cleanup and decommissioning routine. Researchers said this suggested the operators intended the campaign to have a finite lifecycle.
Trellix observed a notable spike in mining activity on December 8, 2025. The increase was associated with a bespoke XMRig deployment chain designed for stealth, persistence, and improved RandomX mining performance.
Researchers observed low but rising mining-pool activity beginning in December 2025, indicating the operation was becoming more active. Trellix characterized the malware as a resilient botnet using BYOVD via the vulnerable WinRing0x64.sys driver tied to CVE-2020-14979.
Trellix reported that the custom XMRig cryptojacking operation was active on a limited basis through November 2025. The campaign used pirated software installers to deliver a multi-stage miner with persistence, privilege escalation, and worm-like USB propagation.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.