FILEMembers
FILE

One lolMiner Kit, Repackaged 20 Ways, Beats Static Detection

Twenty of forty-three file indicators trace back to a single unsigned lolMiner-based cryptomining toolkit, copied and renamed across batch scripts, shell scripts, VBA loaders and one EXE. Detection ratios swing from 0/73 to 33/76 purely on packaging, not payload, while the kit spreads across 40+ countries and six industry verticals.

Jun 27, 2026, 05:44 (UTC+9)Last seenJul 2, 2026Severity72ByCTX TeamIOC49MITRE48RegionsAUBEBRCACH

Twenty of the forty-three file indicators feeding this campaign are not independent malware samples — they are one dropped cryptomining toolkit, copied and renamed across batch scripts, shell scripts, a VBA-tagged loader pair, a ZIP archive and a single compiled Windows binary. Every one of them shares the identical directory scaffold resources/bin/lolminer/1.98a/ and duplicated install paths under %ProgramFiles%\CommonProgramFiles(x86)\microsoft shared\{bc4eaae6|71d5719f}\lolminer\1.98a\.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence