Hackers Exploit Windows Tool to Deploy Crypto-Mining Malware

Mining
Author
Author
Fredrik Vold
Last updated: 
Why Trust Cryptonews
Cryptonews has covered the cryptocurrency industry topics since 2017, aiming to provide informative insights to our readers. Our journalists and analysts have extensive experience in market analysis and blockchain technologies. We strive to maintain high editorial standards, focusing on factual accuracy and balanced reporting across all areas - from cryptocurrencies and blockchain projects to industry events, products, and technological developments. Our ongoing presence in the industry reflects our commitment to delivering relevant information in the evolving world of digital assets. Read more about Cryptonews
Source: AdobeStock / Tomasz Bidermann

Hackers have targeted a popular Windows-based software packaging tool to infect computers with crypto mining malware, IT security firm Cisco Talos Intelligence Group has revealed.

The mining attack on computers happens through a Windows tool known as Advanced Installer, and the attackers have used the tool to package malicious code together with software installers from popular tools like Adobe Illustrator, Autodesk 3ds Max and SketchUp Pro.

The software tools affected are used specifically for 3-D modeling and graphic design, and mainly use the French language, the firm said.

Infected software installers. Source: Cisco Talos Intelligence Group

Cisco Talos’ report explained that once infected, the computers, which are often used by graphic designers and therefore have powerful Graphics Processing Units (GPU), are then used to mine crypto on behalf of the attacker.

“The campaign likely affects business verticals such as architecture, engineering, construction, manufacturing and entertainment, as the attackers use software installers specifically created for 3-D modeling and graphic design,” the report said.

It added that these industries are attractive targets for the hackers because powerful GPUs are highly useful for mining various cryptocurrencies.

Once infected, the computers start running the M3_Mini_Rat tool, which allows attackers to download and run the Ethereum malware miner PhoenixMiner and the multi-coin mining malware lolMiner.

Among the most popular proof-of-work (PoW) cryptocurrencies that can be mined with GPUs today is the Ethereum fork Ethereum Classic (ETC) and the privacy-focused coin Monero (XMR).

Bitcoin (BTC) is generally mined on more specialized mining machines known as ASICs.

The firm said the activity has been ongoing since “at least November 2021,” and victims are spread out around the world but with a concentration in France and other French-speaking regions.

Source: Cisco Talos Intelligence Group

Logo

Why Trust Cryptonews

2M+
Active Monthly Users Around the World
250+
Guides and Reviews Articles
8
Years on the Market
70
International Team Authors
editors
+ 66 More

Best Crypto ICOs

Discover trending tokens still in presale — early-stage picks with potential

Explore Our Tools

Smart tools made for everyday crypto users

Market Overview

  • 7d
  • 1m
  • 1y
Market Cap
$3,363,908,624,460
-1.73
Trending Crypto

More Articles

Blockchain News
Russian Power Firm Launches Bitcoin Mining Mutual Investment Fund
Tim Alper
Tim Alper
2025-06-19 23:30:00
Price Analysis
XRP Price Prediction: Analyst Says $8 Is Just the Beginning Now That SEC Risk Is Gone
Alejandro Arrieche
Alejandro Arrieche
2025-06-19 23:01:00
Crypto News in numbers
editors
Authors List + 66 More
2M+
Active Monthly Users Around the World
250+
Guides and Reviews Articles
8
Years on the Market
70
International Team Authors