Unit 42 researchers uncovered a financially motivated campaign active in April 2026 delivering Vidar stealer and XMRig cryptocurrency miner via malvertising disguised as cracked software. The campaign uses the Factory-v3 malware-as-a-service builder, which generates Go-compiled loaders with per-build unique hashes to defeat hash-based detection. Key evasion techniques include: rogue Authenticode certificates impersonating JustWatch and later BleacherReport, file-size inflation up to 491 MB using null byte padding to bypass sandbox size limits, DLL sideloading via a fake MpClient.dll, and an in-memory AMSI bypass that patches AmsiScanBuffer. The attack chain drops Vidar stealer (targeting browser credentials, cookies, and crypto wallets) and XMRig (mining Monero via pool.supportxmr.com), with persistence via registry Run keys, scheduled tasks, and a startup batch script. The operator uses Telegram for infection notifications under the 'X3D MINER' moniker. Full IOCs including SHA256 hashes, C2 IPs, file paths, and certificate details are provided.

13m read timeFrom unit42.paloaltonetworks.com
Post cover image
Table of contents
Executive SummaryAttack TimelineInitial Access: Malvertising via Fake Software CracksFactory-v3/UpdateFactory BuilderRogue Authenticode CertificateSample ClustersFile-Size InflationAMSI BypassAttack ChainPersistence MechanismsX3D MINERVariant BConclusionIndicators of CompromiseAdditional Resources
358 Impressions