Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

XMRig Malware Disables Windows Updates and Scheduled Tasks to Maintain Persistence

Monero (XMR), a cryptocurrency, saw a spectacular surge in early 2025, rising 45% from $196 to $285 by May, with a notable peak in April. This surge coincided with a high-profile Bitcoin theft in the US, where the stolen assets were reportedly converted…

Monero (XMR), a cryptocurrency, saw a spectacular surge in early 2025, rising 45% from $196 to $285 by May, with a notable peak in April. This surge coincided with a high-profile Bitcoin theft in the US, where the stolen assets were reportedly converted into Monero by a single individual, drawing attention to the privacy-focused coin. Amidst this financial uptick, the legitimate Monero mining tool XMRig received substantial optimization updates in April, potentially attracting both legitimate users and threat actors to exploit its capabilities. Rise of a Cryptomining Threat However, a new wave of malicious XMRig variants has emerged, showcasing sophisticated attack chains and targeting a broader range of countries, including Russia, Belgium, Greece, and China, unlike the 2023 versions which primarily impacted Russia, Azerbaijan, and Uzbekistan. Key stages of the recent XMRig cryptomining attack.evade detection, and establish persistence using pre-installed Windows tools like PowerShell. The latest XMRig malware campaign begins with an unknown initial infection vector, but its malicious behavior is triggered when svchost.exe spawns a cmd process to execute a batch file, dubbed 1.cmd. According to the Report, this script checks for a marker file (check.txt) in the %APPDATA%\Temp directory to avoid re-infection, then modifies Windows Defender registry settings to exclude the C:\ path from scans. It downloads a second script, S2.bat, from the suspicious domain notif[.]su, a newly registered site with minimal antivirus detection at the time of discovery, and executes it hidden from the user via PowerShell. S2.bat further solidifies its foothold by disabling critical Windows services like Wuauserv (Windows Update Service), BITS, and TrustedInstaller, alongside update-related scheduled tasks to prevent system patches that could remove the malware. A Multi-Staged Attack Chain It then downloads a malicious XMRig miner (miner.exe) from notif[.]su, which installs itself with persistence mechanisms including a registry entry under HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\DJKONTAH and drops a legitimate WinRing0 driver for privilege escalation. Notably, the scripts lack obfuscation, featuring plain-text comments that suggest creation by large language models (LLMs) or inexperienced “script kiddies,” yet their simplicity proved effective with low detection rates on platforms like VirusTotal during initial discovery. Open-source intelligence indicates the domain notif[.]su was taken down weeks after updates to the malware files ceased in mid-April 2025. This XMRig variant demonstrates how even basic malware with unobfuscated behaviors can bypass defenses through LOLBAS tactics. Solutions like G DATA’s Extended Detection and Response (XDR) can detect such activities based on behavioral analysis, offering critical protection. Users should remain vigilant for signs of infection, such as suspicious network traffic to domains like notif[.]su or unexpected files in system directories. Indicators of Compromise (IOCs) File/DomainSHA256 HashDetection Name1. cmda57688c151a42d8a2b78f72d23ae7e6c2d6a458edd50f0a4649cc630614763b0Script.Trojan-Downloader.Agent.BSDS2.bat3acf8d410f30186a800d5e8c3b0b061a6faf7c0939b129d230de42e9034ce6c3Script.Trojan.Coinminer.EFminer.exef4386aaa87c922d5d7db28d808ad6471b1c4deb95d82a9e6cfe8421196c5610bWin64.Trojan-Dropper.Coinminer.857JR9notif[.]suN/AN/A Stay Updated on Daily Cybersecurity News. Follow us on Google News, LinkedIn, and X.

Based on reporting by GBHackers.

Monero (XMR), a cryptocurrency, saw a spectacular surge in early 2025, rising 45% from $196 to $285 by May, with a notable peak in April.
Derek Vaughn · Thehackingpost
Advertisement
AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories