Researchers reported a malware campaign delivering a modified SilentCryptoMiner alongside a remote access trojan through illegal movie, TV, and digital library websites that pushed fake video player plugin updates. The infection chain used a ZIP archive containing a legitimate executable and a malicious DLL for DLL side-loading, then triggered stack-overflow-based ROP decryption and reflective loading to deploy the main module, a watchdog component, the RAT, and CPU/GPU miners.
The activity appears to extend operations seen since at least 2022, with refreshed infrastructure and delivery sites but largely unchanged archive structure and execution logic. The malware used DNS tunneling and date-based domain generation for execution gating and command-and-control, disabled security and power-saving features when it gained elevated privileges, and established persistence through a fake GoogleUpdateTaskMachineQC service; researchers said the campaign had substantial exposure because the affected piracy-related sites drew roughly 40 million visits in April 2026.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
In late April 2026, Kaspersky reported that the malware delivered via fake plugin updates was a modified SilentCryptoMiner fork that used junk code, a stack overflow, and a ROP chain to decrypt and reflectively load its payload in memory. The analysis also said it collected hardware identifiers and exfiltrated them through DNS tunneling, and when run as administrator it disabled security controls, deleted Microsoft's Malicious Software Removal Tool, and altered power settings to support mining.
On 2026-05-29, Gurucul published a high-severity notice on the piracy-site malware activity, including domains, an IP address, and MD5 hashes as indicators of compromise. The notice also provided threat detection and incident-response queries to help identify related domain, IP, and file-hash activity.
In late April 2026, researchers investigated infections delivered through illegal movie, TV, and digital library websites via fake video player plugin updates. The malware was distributed as a ZIP archive containing a legitimate executable and a malicious DLL used for DLL side-loading to deploy a miner, watchdog, and RAT components.
The infected illegal movie, TV, and digital library websites collectively received about 40 million visits in April 2026, indicating the campaign's potentially large reach.
Researchers assessed the piracy-site malware campaign as a continuation of activity that has been ongoing since at least 2022, with largely unchanged archive structure and infection logic despite updated infrastructure and delivery sites.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecommunity.gurucul.com
Open sourcecybersecuritynews.com
Open sourcecommunity.gurucul.com
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.