Check Point Research reported that the Nitrokod malware campaign distributed cryptomining malware by disguising it as legitimate desktop software, most notably fake Google Translate Desktop installers promoted through free software websites and search results. The Turkish-speaking operation had reportedly been active since 2019 and may have infected thousands of systems across 11 countries by luring users into downloading Trojanized applications that appeared benign.
The malware used a lengthy multi-stage infection chain designed to evade detection, including delays of days or weeks, scheduled tasks, self-deletion, log clearing, and checks for security products before deploying its final payload. Once established, Nitrokod installed XMRig and a controller component named powermanager.exe, then contacted command-and-control infrastructure to retrieve configuration data and begin mining cryptocurrency on compromised Windows machines.

Get the infrastructure and lures behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Check Point Research detected the previously undisclosed Nitrokod cryptomining campaign at the end of July 2022. Its analysis linked the fake application installers to a multi-stage malware chain that deployed XMRig miners on victim systems.
Check Point Research said the Turkish-speaking Nitrokod campaign had been active since 2019, distributing trojanized desktop applications through free software sites and search results, especially fake Google Translate Desktop installers. The campaign ultimately infected thousands of machines across 11 countries.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 10 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.