
17-Year-Old Kernel Driver Powers 2026 Monero Mining Campaign
A financially motivated campaign active June 19–20, 2026 deploys XMRig 6.26.0 behind a three-layer evasion stack anchored by WinRing0x64.sys, a LOLDrivers-listed vulnerable kernel driver first seen in 2009. The toolchain pairs a self-signed loader with a game-themed NSIS dropper, backed by C2 infrastructure registered just four days before the campaign peaked.
A financially motivated campaign active during the week of June 19–20, 2026 is deploying XMRig 6.26.0 Monero miners behind a three-layer evasion stack that most commodity cryptomining operations never bother to assemble: a LOLDrivers-listed vulnerable kernel driver to undermine endpoint defences, a self-signed loader dressed up with a same-day certificate to slip past casual signature checks, and a game-themed NSIS dropper to carry the whole package past users who think they are installing a…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read