The Stantinko botnet, a long-running operation with roughly 500,000 compromised machines, expanded its criminal activity by deploying a heavily modified and obfuscated version of the open-source xmr-stak miner to generate Monero on infected systems. The activity was observed from at least August 2018 and primarily affected users in Russia, Ukraine, Belarus, and Kazakhstan, adding cryptomining to a botnet already known for large-scale abuse.
The mining module used multiple evasion and resilience techniques to avoid detection and disruption. It retrieved mining proxy addresses from YouTube video descriptions, communicated with those proxies over TCP using RC4 encryption and Base64 encoding, and downloaded hashing code at runtime so core mining logic was not stored on disk. It also attempted to suppress competing miners, paused activity when running on battery power or when task-manager tools were detected, and scanned for security software using CRC-32-hashed process names. The abused YouTube channels used for proxy configuration were reported and removed.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
Researchers analyzed a new cryptomining module used by the Stantinko botnet and documented unusual string obfuscation, source-level control-flow flattening, dead code, and do-nothing code designed to hinder reverse engineering and detection. They also described a binary-level deobfuscation method to reconstruct executable code while removing dead dispatches.
Since at least August 2018, Stantinko operators monetized infected systems by deploying a heavily modified and obfuscated xmr-stak-based module to mine Monero on compromised machines.
The Stantinko botnet had been active since at least 2012, establishing the start of the long-running criminal operation later associated with multiple monetization schemes.
YouTube channels whose video descriptions were used by the malware to distribute mining proxy configuration were reported and subsequently taken down.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 62 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.