Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators A miner with a side of RAT: the unintended gift with your TV show or book

r7mvjl67.space

TLP:CLEAR
Active

Domain

Description

A cybercrime campaign active since at least 2022 has been distributing cryptocurrency miners and RAT malware through illegal streaming sites and digital libraries. Victims are tricked via fake video player plugin updates or browser crash pages into downloading ZIP archives containing legitimate executables and malicious DLLs. The malware employs DLL side-loading, establishes persistence through Windows services, and deploys multiple components including XMRig-based CPU miners, GPU miners, a watchdog module, and a RAT agent with remote control capabilities. The campaign leverages highly popular pirated content sites with monthly traffic reaching up to 40 million visits, significantly expanding the potential victim pool. The malware includes sophisticated anti-detection features, DNS tunneling for command-and-control, and domain generation algorithms based on dates.

Sightings (0)

No sightings recorded yet

Details

Name / Label
A miner with a side of RAT: the unintended gift with your TV show or book
Pattern Type
STIX
Confidence
75%
Valid From
May 28, 2026 23:06
Total Sightings
0
Added
May 28, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of r7mvjl67.space

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.