Researchers reported two distinct cryptomining operations that used stealth and defense-evasion techniques to gain and keep access on victim systems. In the GhostEngine campaign, attackers deployed vulnerable drivers in a bring-your-own-vulnerable-driver (BYOVD) technique to terminate endpoint detection and response products and other security controls, clearing the way for cryptocurrency miners to run on compromised Windows machines. The activity highlighted how legitimate but flawed kernel drivers can be weaponized to disable protections before payload execution.
A separate campaign, GuptiMiner, abused antivirus update mechanisms to distribute backdoors and mining components through what appeared to be trusted software delivery paths. According to researchers, the operation combined supply-chain-style tampering with persistence and remote access, allowing attackers to install additional malware while quietly consuming system resources for mining. Together, the incidents show attackers increasingly pairing cryptomining with privileged evasion methods and trusted update abuse to bypass defenses and monetize compromised endpoints.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
BleepingComputer reported on GhostEngine attacks that leveraged vulnerable drivers in a bring-your-own-vulnerable-driver technique to kill endpoint detection and response protections before deploying crypto-mining malware. The reporting highlighted the attackers' use of driver abuse to evade security controls on compromised systems.
Gen Digital disclosed a campaign dubbed GuptiMiner that abused antivirus update mechanisms to distribute backdoors and cryptocurrency-mining payloads. The activity showed attackers using trusted security software channels to gain persistence and monetize infected systems.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.