The Umnr_-prefixed loader is a Themida-packed SilentCryptoMiner loader that injects a watchdog into conhost.exe and a miner into explorer.exe.
SilentCryptoMiner
SilentCryptoMiner is a Windows-focused covert cryptocurrency miner derived from the open-source XMRig miner.
SilentCryptoMiner
Family profile
SilentCryptoMiner is a Windows-focused covert cryptocurrency miner derived from the open-source XMRig miner. It hijacks victim CPU and GPU resources to mine Monero and, depending on build configuration, may support other cryptocurrencies and mining algorithms. Documented variants use direct system calls, process injection or process hollowing, anti-analysis checks, and suspension of mining when security or analysis tools are detected. Some variants use the WinRing0 driver to tune processor settings for improved mining performance.
SilentCryptoMiner establishes persistence through scheduled tasks, services, or user-level autorun mechanisms, and can disable sleep and hibernation to maximize mining uptime. Certain variants inject a watchdog into a Windows process; the watchdog monitors the miner and restores removed payloads and persistence artifacts. A later campaign variant collected hardware identifiers and exfiltrated them through DNS tunneling disguised as benign traffic. That campaign also used DLL side-loading, in-memory reflective loading, and, when elevated, disabled security controls.
SilentCryptoMiner has been distributed through trojanized or fake software installers, fake VPN and network-restriction-bypass tools, fake media-player or browser-update prompts on pirated-content sites, and steganographically embedded components. The financially motivated cluster tracked as REF1695 deployed SilentCryptoMiner alongside remote-access malware and custom XMRig loaders in fake-installer campaigns active since late 2023. Other campaigns particularly targeted Russian Windows users with trojanized restriction-bypass utilities.
Capabilities
- Byovd
- Crypto Theft
- Defense Evasion
- Dll Sideloading
- Exfiltration
- Persistence
- Process Injection
- Reconnaissance
Samples
Recent samples
1 sandbox sample in the Derp library, newest 1 shown
Reported operators
Threat actors
1 named in public reportingMITRE ATT&CK
SilentCryptoMiner in ATT&CK
50 distinct techniquesTechniques
50 techniquesReporting
Research mentioning SilentCryptoMiner
Inside Two Multi-Stage Attack Chains Hiding Behind Job Offers - Malware News - Malware Analysis, News and Indicators
Two recruitment-themed malware campaigns use decoy job documents to deliver multi-stage, memory-resident implants after a single click. One campaign distributes a ZIP archive containing a renamed WinWord.exe that DLL-side-loads a malicious component to deploy PureRAT/ResolverRAT; researchers assess its infrastructure and tradecraft as overlapping with the Vietnam-nexus PXA Stealer criminal cluster. The other disguises an LNK shortcut as a PDF, invokes mshta.exe, and retrieves a custom native implant that decrypts and reflectively maps its DLL payload in memory. The second operation has not been attributed to a known threat actor. Both chains reduce Windows telemetry and analysis visibility through sandbox-evasion measures and Task Scheduler COM-based persistence rather than schtasks.exe, while providing attackers remote-access capability. The PureRAT campaign adds scheduled tasks, WMI event subscriptions, COM hijacking, and mirrored staging directories that can restore removed artifacts. The activity follows prior reporting on job-offer social engineering used to deploy Pure-family malware, including PureHVNC and PureRAT-linked tooling, and shows the continued use of this ecosystem alongside heavily obfuscated loaders and persistence mechanisms.