Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Advanced Crypto Mining Malware Spreads Through External Drives and Air-Gapped Systems

An advanced cryptocurrency mining campaign has been identified, targeting systems via external storage devices and capable of infiltrating air-gapped environments.

An advanced cryptocurrency mining campaign has been identified, targeting systems via external storage devices and capable of infiltrating air-gapped environments.

The malware executes a multi-stage infection process, focusing on mining Monero cryptocurrency and establishing persistent mechanisms to resist removal.

Differing from typical cryptojacking operations, this campaign utilizes kernel-level exploitation and worm-like propagation capabilities.

The attack initiates via pirated software bundles disguised as legitimate office productivity suite installers.

Upon execution, the malware deploys multiple components that coordinate to maintain the infection and maximize mining output.

The operation includes watchdog processes that create a self-healing architecture, where terminating one component triggers others to restore it within seconds.

The threat is particularly concerning due to its propagation method. Analysts identified the campaign's ability to monitor for newly connected external drives. When users insert USB flash drives or external hard disks, the malware automatically copies itself to the device and creates hidden folders with deceptive shortcuts.

The malware executes a multi-stage infection process, focusing on mining Monero cryptocurrency and establishing persistent mechanisms to resist removal.
Nathan Cole · Thehackingpost

This mechanism enables lateral movement across networks and can breach air-gapped systems via physical media transfer.

The malware's architecture separates command logic from execution logic, with the controller handling monitoring and decision-making while remaining lightweight to avoid detection by security software.

Separate payload components manage resource-intensive mining operations and employ aggressive defensive actions, including terminating security tools or legitimate Windows Explorer processes.

Kernel-Level Exploitation and Performance Optimization

The most technically advanced component involves a Bring Your Own Vulnerable Driver technique. The malware deploys WinRing0x64.sys, a legitimate but vulnerable driver component containing CVE-2020-14979.

This vulnerability enables the acquisition of Ring 0 kernel privileges, bypassing the operating system's hardware abstraction layer.

Advertisement

Through kernel access, the malware modifies CPU Model Specific Registers to disable hardware prefetchers that interfere with the RandomX mining algorithm's efficiency. This optimization increases the Monero mining hashrate by 15 to 50 percent.

The technique achieves performance improvements without writing a malicious driver, instead utilizing the valid digital signature of the vulnerable legacy driver.

The campaign incorporates temporal controls, with hardcoded logic checking the system date against December 23, 2025. Before this date, the malware executes infection routines, but afterward, it triggers a cleanup mode that terminates components and deletes dropped files, indicating a planned operational lifecycle.

Organizations are advised to enforce Microsoft's Vulnerable Driver Blocklist through Windows Defender Application Control to prevent vulnerable drivers from loading. Implementing device control policies to restrict removable media can cut off the worm's propagation vector.

Security teams should configure web filtering to block outbound connections to consumer-grade mining pools and enforce security awareness training to highlight the risks associated with pirated software.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories