C&CMembers
C&C

17-Year-Old Kernel Driver Powers 2026 Monero Mining Campaign

A financially motivated campaign active June 19–20, 2026 deploys XMRig 6.26.0 behind a three-layer evasion stack anchored by WinRing0x64.sys, a LOLDrivers-listed vulnerable kernel driver first seen in 2009. The toolchain pairs a self-signed loader with a game-themed NSIS dropper, backed by C2 infrastructure registered just four days before the campaign peaked.

Jun 21, 2026, 04:14 (UTC+9)Last seenJun 21, 2026Severity100ByCTX TeamIOC57MITRE36

A financially motivated campaign active during the week of June 19–20, 2026 is deploying XMRig 6.26.0 Monero miners behind a three-layer evasion stack that most commodity cryptomining operations never bother to assemble: a LOLDrivers-listed vulnerable kernel driver to undermine endpoint defences, a self-signed loader dressed up with a same-day certificate to slip past casual signature checks, and a game-themed NSIS dropper to carry the whole package past users who think they are installing a…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence