FILEMembers
FILE

Autodesk Licensing Agent Hijacked to Drop Coinminer via DLL Sideload

A trojanized Autodesk Network License Manager crack package uses a malicious version.dll to hijack the legitimate AdskLicensingAgent service, routing cryptocurrency mining traffic through Cloudflare-proxied C2 domains backed by a Russian /24. A freshly compiled .NET dropper introduced days before analysis suggests the operator is actively expanding post-compromise capabilities.

Jun 11, 2026, 02:44 (UTC+9)Last seenJun 11, 2026Severity100ByCTX TeamIOC17MITRE53RegionsBR

A trojanized crack package impersonating Autodesk's Network License Manager is exploiting the legitimate AdskLicensingAgent service to load attacker-controlled code — a DLL sideload [T1574.002] that turns a trusted enterprise software component into an unwitting execution vehicle. The lure is polished enough to have drawn 461 submissions from 417 unique sources since late March 2026, and the campaign's evasion layer is effective enough that one major automated sandbox rated the primary payload…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence