Researchers reported two malware campaigns that install cryptocurrency miners through trojanized downloads delivered from pirate streaming sites and fake software portals. In one operation, users visiting illicit movie and TV sites were shown a bogus video-plugin update that delivered a ZIP archive containing a legitimate executable and a malicious DLL; the DLL sideloaded a multi-stage miner framework with persistence, defense evasion, a watchdog, a RAT component, and CPU/GPU mining modules. The malware, a modified fork of SilentCryptoMiner, used DNS tunneling for execution gating, installed a service named GoogleUpdateTaskMachineQC, weakened Windows defenses, injected into conhost.exe and explorer.exe, and communicated through rotating domains and infrastructure tied to 107[.]172[.]212[.]235.
Microsoft described a related cryptojacking-focused campaign aimed at owners of high-performance PCs, using fake downloads of popular utilities and hardware-monitoring tools that were promoted through SEO poisoning and, more recently, surfaced in AI assistant recommendations. Those ZIP archives also paired a legitimate executable with a malicious DLL for sideloading, then installed ScreenConnect for persistent remote access, set registry autoruns and scheduled tasks, added Microsoft Defender exclusions, checked for analysis tools, and used process hollowing to launch payloads inside trusted Windows processes. After profiling infected systems, the attackers fetched GPU miners including gminer, lolMiner, and SRBMiner-MULTI; researchers warned the access could support not only cryptomining but also data theft, lateral movement, and eventual ransomware deployment.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Xakep reported Microsoft's findings on the campaign that abuses fake software downloads and AI assistant recommendations to deliver malware and GPU miners to powerful PCs.
Microsoft researchers identified a malware campaign that lured owners of high-performance PCs with fake downloads of popular utilities and hardware monitoring tools. The malware used DLL sideloading, installed ScreenConnect for persistent remote access, established persistence and Defender exclusions, and then deployed GPU-focused cryptocurrency miners.
Microsoft researchers said that by spring 2026 they observed malicious domains from a cryptojacking campaign appearing in AI assistant responses when users asked where to download popular software. The campaign had previously relied on SEO poisoning before expanding to this delivery vector.
Kaspersky disclosed technical analysis of the pirate-site campaign, including its modified SilentCryptoMiner fork, DNS-tunneling execution gating, persistence via GoogleUpdateTaskMachineQC, RAT communications, hashes, detections, and C2 indicators.
Kaspersky reported that the infected pirate resources associated with the campaign collectively received about 40 million visits in April 2026, indicating potentially large exposure.
Researchers investigated an infection in late April 2026 in which users visiting pirate streaming sites were shown a fake video-plugin update prompt that delivered a ZIP archive containing a legitimate executable and a malicious DLL for sideloading. The resulting malware chain installed a multi-stage miner framework with persistence, defense evasion, a watchdog, a RAT component, and CPU/GPU mining modules.
Kaspersky said the miner campaign delivered via pirate movie and TV streaming resources appears to be a continuation of broader activity that has been active since at least 2022.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.