
A Miner Wearing the Face of a Visual C++ Runtime
A packed .NET coinminer disguised as msvcp110.exe has replaced dropper payloads in a campaign CTX Team has tracked since April. The new binary communicates with a persistent single-node C2 on Contabo, marking a pivot from delivery-stage malware to direct resource hijacking.
##A Miner Wearing the Face of a Visual C++ Runtime A packed .NET coinminer masquerading as the Microsoft Visual C++ runtime file msvcp110.exe has replaced the dropper payloads in a campaign CTX Team has been tracking since April, marking a clear pivot from delivery-stage malware to direct resource hijacking. The new primary binary — a 774 KB PE32+ assembly first submitted on 2026-04-17 — deploys into C:\Users\[user]\AppData\Roaming\msvcp110_win\msvcp110.exe, a user-writable path whose filename…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read