Skip to main content

Hackers modify ransomware to deliver a Coinhive cryptocurrency-mining payload

Trend Micro recently discovered that hackers repurposed the XiaoBa ransomware to carry a cryptocurrency miner payload. Typically, XiaoBa infects a PC, encrypts its files, and holds those files hostage until the victim delivers a payment to hackers. But in this case, the new payload injects the Coinhive mining script into HTM and HTML files used by the infected PC. 

Coinhive is a JavaScript-based component that is injected into webpages. It uses a visiting PC’s processor to mine digital coins in the background although computers take a noticeable performance hit during the process. Typically, the mining ends once you leave the Coinhive-infested page, bringing your processor’s performance back up to speed. But Coinhive can also secretly reside in browser extensions, making an escape from the grueling process impossible while the browser remains open. 

The new XiaoBa variant appears to have a worm-style component, meaning it could spread from PC to PC connected to a local network, thus increasing the hackers’ financial gains. But that is not the worst-case scenario: This variant is also highly destructive. The revised code infects legitimate binary files (exe, com, scr, pif) to deliver the payload but destroys these files in the process. 

“The malware will prepend itself to any file with the above extension,” the security firm states. “That is the only criteria checked before infection, unlike other malware that typically look for certain conditions or markers before infecting the file. It also traverses all directories. It will not avoid critical system files and can render the system critically unstable if it is not dealt with properly.” 

Trend Micro says the malware infects files of all sizes and does not leave any markers on the infected file, allowing for multiple infections — 10 as shown in one example — on a single PC. Thus, not only is the processor bogged down from the mining aspect, but the “stacked” infections consume large amounts of memory and likely a big chunk of disk space, too. 

Trend Micro currently knows of only two versions of the XiaoBa variant, both of which carry the Coinhive payload. Both will disable Windows User Account Control notifications while only one deletes Norton Ghost images, disk media images (ISO), and blocks access to anti-virus and forensic-related websites. Presumably, both inject the Coinhive script into webpages as they are downloaded and cached locally on the PC’s storage device. 

What is not clear is how PCs obtain the XiaoBa variants in the first place. Malware is typically spread through email and social network scams, requiring victims to click a link that downloads the malicious file. According to Trend Micro, one of the two variants propagates by using removable drives, like a USB-based storage stick.  

XiaoBa was first reported by MalwareHunter Team at the end of 2017. Once it lands on a PC, it disguises itself as system files, disables the firewall, and blocks security-focused websites. It also modifies the PC’s registry and allows other viruses to infect the system. That doesn’t even cover the ransomware aspect, which encrypts files until victims pay a ransom. 

Editors' Recommendations

Kevin Parrish
Former Digital Trends Contributor
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
Best Alienware deals: Gaming PCs, laptops, and monitors
Alienware Aurora R15 placed at an angle on a table.

Alienware has been in the game gear industry for two decades or so now, and it keeps coming out with some of the highest-end devices, whether it's gaming laptops, gaming PCs, headsets, or even a gaming chairs. Of course, being a premium brand does also mean that you're going to be paying premium prices, which is why you'll likely want to spring for an Alienware deal if you want to pick up something from the brand. That's why we've gone out and collected our favorite deals for you below, although if you don't quite find what you're looking for, check out some of the best gaming laptop deals and the best gaming PC deals we've put together.
Alienware AW720H wireless gaming headset -- $120, was $150

A gaming headset is a great way to keep in touch with your friends while you play. The Alienware AW720H gaming headset lets you do so without the burden of wires, as it connects to your gaming setup via Bluetooth. It has a built-in microphone for outgoing communications, as well as Dolby Atmos, Surround Sound, and Stereo Sound options to help immerse you in the game and incoming communications.

Read more
Nvidia might power your next handheld gaming PC
Starfield running on the Asus ROG Ally.

Rumor has it that Nvidia is working on a system-on-a-chip (SoC) that could power PCs and even future handheld gaming devices. The speculation comes from Dan Nystedt, who says that Nvidia is working with MediaTek to develop an AI processor that could be revealed as soon as June.

Adding further weight to the rumor is XpeaGPU, who also claims Nvidia is working on a handheld SoC. The leaker says that Nvidia thinks the chip has "good market potential." This isn't the first time we've heard about Nvidia looking at the growing market of handheld gaming PCs, either. In March, leaker Moore's Law is Dead claimed that Nvidia is "worried that it's missing the boat here" with handheld gaming PCs.

Read more
ChatGPT not working? The most common problems and fixes
A person typing on a laptop that is showing the ChatGPT generative AI website.

ChatGPT is one of the most popular AI chatbots available today. Many favor the tool because it is easy to access and use; however, it is not perfect. ChatGPT is also known for down times and technical issues that can prevent you from having access to the chatbot exactly when you need it for a specific task.

There are many reasons ChatGPT might fail to work. Some challenges might arise on the side of the parent company, OpenAI, and some might come up because of your own environment. Luckily, most mishaps are typically easy to resolve with a bit of troubleshooting.

Read more