
Autodesk Licensing Agent Hijacked to Drop Coinminer via DLL Sideload
A trojanized Autodesk Network License Manager crack package uses a malicious version.dll to hijack the legitimate AdskLicensingAgent service, routing cryptocurrency mining traffic through Cloudflare-proxied C2 domains backed by a Russian /24. A freshly compiled .NET dropper introduced days before analysis suggests the operator is actively expanding post-compromise capabilities.
A trojanized crack package impersonating Autodesk's Network License Manager is exploiting the legitimate AdskLicensingAgent service to load attacker-controlled code — a DLL sideload [T1574.002] that turns a trusted enterprise software component into an unwitting execution vehicle. The lure is polished enough to have drawn 461 submissions from 417 unique sources since late March 2026, and the campaign's evasion layer is effective enough that one major automated sandbox rated the primary payload…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read