Skip to main content

Hackers modify ransomware to deliver a Coinhive cryptocurrency-mining payload

Trend Micro recently discovered that hackers repurposed the XiaoBa ransomware to carry a cryptocurrency miner payload. Typically, XiaoBa infects a PC, encrypts its files, and holds those files hostage until the victim delivers a payment to hackers. But in this case, the new payload injects the Coinhive mining script into HTM and HTML files used by the infected PC. 

Coinhive is a JavaScript-based component that is injected into webpages. It uses a visiting PC’s processor to mine digital coins in the background although computers take a noticeable performance hit during the process. Typically, the mining ends once you leave the Coinhive-infested page, bringing your processor’s performance back up to speed. But Coinhive can also secretly reside in browser extensions, making an escape from the grueling process impossible while the browser remains open. 

Recommended Videos

The new XiaoBa variant appears to have a worm-style component, meaning it could spread from PC to PC connected to a local network, thus increasing the hackers’ financial gains. But that is not the worst-case scenario: This variant is also highly destructive. The revised code infects legitimate binary files (exe, com, scr, pif) to deliver the payload but destroys these files in the process. 

Please enable Javascript to view this content

“The malware will prepend itself to any file with the above extension,” the security firm states. “That is the only criteria checked before infection, unlike other malware that typically look for certain conditions or markers before infecting the file. It also traverses all directories. It will not avoid critical system files and can render the system critically unstable if it is not dealt with properly.” 

Trend Micro says the malware infects files of all sizes and does not leave any markers on the infected file, allowing for multiple infections — 10 as shown in one example — on a single PC. Thus, not only is the processor bogged down from the mining aspect, but the “stacked” infections consume large amounts of memory and likely a big chunk of disk space, too. 

Trend Micro currently knows of only two versions of the XiaoBa variant, both of which carry the Coinhive payload. Both will disable Windows User Account Control notifications while only one deletes Norton Ghost images, disk media images (ISO), and blocks access to anti-virus and forensic-related websites. Presumably, both inject the Coinhive script into webpages as they are downloaded and cached locally on the PC’s storage device. 

What is not clear is how PCs obtain the XiaoBa variants in the first place. Malware is typically spread through email and social network scams, requiring victims to click a link that downloads the malicious file. According to Trend Micro, one of the two variants propagates by using removable drives, like a USB-based storage stick.  

XiaoBa was first reported by MalwareHunter Team at the end of 2017. Once it lands on a PC, it disguises itself as system files, disables the firewall, and blocks security-focused websites. It also modifies the PC’s registry and allows other viruses to infect the system. That doesn’t even cover the ransomware aspect, which encrypts files until victims pay a ransom. 

Kevin Parrish
Former Digital Trends Contributor
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
AMD’s new 9070 XT beats all but one Radeon GPU
RX 7900 XTX and RX 7900 XT on a pink background.

AMD's RX 9070 XT is the new king of AMD's hill and that goes for almost everything that came before, too. Although AMD didn't market its new card as a high-end option, it might as well have, because it can beat almost any other AMD graphics card you pit it against. Even potentially the AMD RX 7900 XT.

But that last-gen card does have more memory, compute units, and RT accelerators -- even if it's an older design. Let's see how these two cards compare.
Pricing and availability
The AMD RX 7900 XT launched in December 2022, with a price tag of $900. It was an odd choice at the time, as AMD's much-faster 7900XTX was only $100 more, but as prices came down over its generation it became a great 4K value buy towards the end of its lifecycle. It can currently be found for around $900 again, after recent GPU price gouging sent it back up.

Read more
Samsung wants to speed up the OLED takeover
Jacob Roach playing a game on the Samsung Odyssey OLED G6 monitor.

Samsung is one of the main manufacturers of OLED displays, and according to a Newsroom post from yesterday, it wants to push adoption of the technology even further this year. Aiming to increase shipments by 50% with new affordable models, the company could have a big impact on the OLED industry moving forward.

Samsung currently holds a big majority in the OLED market, achieving a 71% share of panels for monitors last year. It's probably no exaggeration to say that wherever Samsung tries to take OLED is where OLED will go. The focus is on monitor panels right now, but once the tech starts to decrease in price, it should affect all types of OLED displays.

Read more
MSI could be working on a Nvidia GPU to finally beat the RTX 4090
Fans on the RTX 5080.

One leak could be a fluke, but two leaks? MSI might be cooking. As per (now) two leaked images, MSI might have an exciting new GPU in the works, and it'd be one that could rival some of the best graphics cards. The GPU in question is another version of the RTX 5080, but this time, it's said to come with 24GB memory -- a major upgrade over the base version. This could finally push it past the RTX 4090, but will it really happen?

Both leaks were spotted by VideoCardz, but surprisingly, MSI itself is the original source for both stories. First, the company posted a promotional video showcasing the RTX 5080 Vanguard GPU, and on the box, it's advertised as "24GB GDDR7." This is an extra 8GB VRAM over the RTX 5080 that's currently available. Coincidentally, it's also the exact same memory capacity as the RTX 4090.

Read more