{"id":234580,"date":"2026-04-04T02:43:23","date_gmt":"2026-04-04T07:43:23","guid":{"rendered":"https:\/\/lifeboat.com\/blog\/2026\/04\/researchers-uncover-mining-operation-using-iso-lures-to-spread-rats-and-crypto-miners"},"modified":"2026-04-04T02:43:23","modified_gmt":"2026-04-04T07:43:23","slug":"researchers-uncover-mining-operation-using-iso-lures-to-spread-rats-and-crypto-miners","status":"publish","type":"post","link":"https:\/\/lifeboat.com\/blog\/2026\/04\/researchers-uncover-mining-operation-using-iso-lures-to-spread-rats-and-crypto-miners","title":{"rendered":"Researchers Uncover Mining Operation Using ISO Lures to Spread RATs and Crypto Miners"},"content":{"rendered":"<p><a class=\"aligncenter blog-photo\" href=\"https:\/\/lifeboat.com\/blog.images\/researchers-uncover-mining-operation-using-iso-lures-to-spread-rats-and-crypto-miners2.jpg\"><\/a><\/p>\n<p>As recently observed in the <a href=\"https:\/\/thehackernews.com\/2026\/03\/hackers-use-fake-resumes-to-steal.html\">FAUX#ELEVATE<\/a> campaign, \u201cWinRing0x64.sys,\u201d a legitimate, signed, and vulnerable Windows kernel driver, is abused to obtain kernel-level hardware access and modify CPU settings to boost hash rates, thereby enabling performance improvement. The <a href=\"https:\/\/www.sophos.com\/en-us\/blog\/mrbminer-cryptojacking-to-bypass-international-sanctions\">use of the driver<\/a> has been <a href=\"https:\/\/www.morphisec.com\/blog\/proxyshellminer-campaign\/\">observed<\/a> in many <a href=\"https:\/\/www.trellix.com\/blogs\/research\/technical-deep-dive-the-monero-mining-campaign\/\">cryptojacking campaigns<\/a> over the years. The functionality was <a href=\"https:\/\/github.com\/xmrig\/xmrig\/blob\/master\/bin\/WinRing0\/WinRing0x64.sys\">added to XMRig miners<\/a> in December 2019.<\/p>\n<p>Elastic said it also identified another campaign that leads to the deployment of <a href=\"https:\/\/thehackernews.com\/2025\/03\/silentcryptominer-infects-2000-russian.html\">SilentCryptoMiner<\/a>. The miner, besides using direct system calls to evade detection, takes steps to disable Windows Sleep and Hibernate modes, set up persistence via a scheduled task, and uses the \u201cWinring0.sys\u201d driver to fine-tune the CPU for mining operations.<\/p>\n<p>Another notable component of the attack is a watchdog process that ensures the malicious artifacts and persistence mechanisms are restored in the event they are deleted. The campaign is estimated to have accrued 27.88 XMR ($9,392) across four tracked wallets, indicating that the operation is yielding consistent financial returns to the attacker.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>As recently observed in the FAUX#ELEVATE campaign, \u201cWinRing0x64.sys,\u201d a legitimate, signed, and vulnerable Windows kernel driver, is abused to obtain kernel-level hardware access and modify CPU settings to boost hash rates, thereby enabling performance improvement. The use of the driver has been observed in many cryptojacking campaigns over the years. The functionality was added to [\u2026]<\/p>\n","protected":false},"author":427,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1523,45],"tags":[],"class_list":["post-234580","post","type-post","status-publish","format-standard","hentry","category-computing","category-finance"],"_links":{"self":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/234580","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/users\/427"}],"replies":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/comments?post=234580"}],"version-history":[{"count":0,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/234580\/revisions"}],"wp:attachment":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/media?parent=234580"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/categories?post=234580"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/tags?post=234580"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}