
Decade-Old Bundler Trojan Drops Tor-Routed MinerGate on Chemicals Workstations
A UPX-compressed Windows dropper branded as a routine installer has been delivering a repackaged MinerGate 6.8 cryptominer since at least 2016, with both components sharing an F-PROT packer signature that points to a common build pipeline. The miner establishes persistence and routes all outbound traffic through Tor, staging through Ukrainian VPS and Russian bulletproof hosting infrastructure. Both samples defeat automated sandbox analysis despite broad static AV detection.
A 919-kilobyte UPX-compressed Windows executable masquerading as a routine software installer is functioning as the first stage of a two-component cryptomining chain that has been circulating since at least late 2016 and remains actively observed as of mid-2026. The dropper — internally branded "Carambis Installer" and carrying a ROSTPAY LTD.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read