Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors x3d miner

Also known as: tracked as, MuddyWater, education, legal, insurance, technology, manufacturing, MERCURY, Storm-1175

Description

A financially motivated campaign identified in April 2026 delivers Vidar stealer and XMRig cryptocurrency miner to victims worldwide through malvertising. Attackers distribute password-protected archives impersonating cracked software, using Go-compiled loaders built with the Factory-v3 framework. The malware employs sophisticated evasion techniques including rogue Authenticode certificates mimicking JustWatch and BleacherReport, file-size inflation to hundreds of MB with null bytes, and AMSI bypass. Once executed, Vidar stealer exfiltrates browser credentials, cookies and cryptocurrency wallets to C2 infrastructure, while XMRig mines Monero cryptocurrency. The operation establishes persistence through registry modifications, scheduled tasks and startup folder scripts. The threat actor, operating under the moniker X3D MINER, primarily targets victims in the U.S. and European Union through a dual-monetization scheme combining credential theft and cryptojacking.

Goals & Targeting

Targeted Sectors

Financial services
Defense
Government
Media
Healthcare
Manufacturing
Critical infrastructure
Hospitality
Education
Utilities
Mining
Information technology
Energy
Non profit
Food agriculture
Entertainment
Transportation
Maritime
Construction
Aviation
Telecommunications

Targeted Countries / Regions

United States of America
FR
IR
CN
RU
TW
AU
BY
GB

AI Analysis

· 1 week ago

Executive Summary

The x3d miner threat actor is a financially motivated group targeting individuals globally through malvertising campaigns. They deploy malware including Vidar stealer and XMRig cryptocurrency miner to steal credentials and hijack computing power for cryptojacking, primarily affecting users in the U.S. and European Union.

Goals & Targeting

The x3d miner's primary strategic objective is financial gain, achieved through two main revenue streams: credential theft for potential sale on darknet markets and cryptojacking to generate Monero cryptocurrency. The targeting focus on individuals likely reflects the ease of large-scale attacks through malvertising, as well as the higher value of targets in the U.S. and EU regions where cryptocurrency adoption is higher. Campaign activities indicate a preference for low-effort, high-yield tactics rather than nation-state espionage.

Enhanced Description

The x3d miner threat actor operates a financially motivated campaign identified in April 2026, delivering malware to victims worldwide through malvertising campaigns. The operation involves distributing password-protected archives impersonating cracked software, leveraging Go-compiled loaders developed with the Factory-v3 framework. These loaders employ sophisticated evasion techniques such as rogue Authenticode certificates mimicking legitimate services like JustWatch and BleacherReport. Additionally, the malware inflates file sizes to hundreds of MB using null bytes and bypasses AMSI detection mechanisms. Once executed, Vidar stealer exfiltrates sensitive information including browser credentials, cookies, and cryptocurrency wallets, while XMRig mines Monero cryptocurrency. The threat actors establish persistence through registry modifications, scheduled tasks, and startup folder scripts. The group primarily targets individuals in the United States and European Union regions, utilizing a dual-moniatization approach combining credential theft and cryptojacking activities.

Key Capabilities

  • Malvertising campaigns
  • Use of sophisticated evasion techniques including rogue certificates and AMSI bypass
  • Deployment of Vidar stealer and XMRig miner
  • Persistence mechanisms through registry, scheduled tasks, and startup scripts
  • Distribution via password-protected archives impersonating cracked software

MITRE ATT&CK Tactics

Adversary Persister
Data Exfiltration
Defense Evasion
Lateral Movement
Malware
System Access Attack

ATT&CK Techniques

T1070
T1045.002
T1055
T1003
T1059
T1566.001

Software / Tooling

Vidar stealer
XMRig miner
Factory-v3 framework
Rogue Authenticode certificates

Campaigns & Victims

The x3d miner threat actors operate a persistent campaign targeting mainly consumers and businesses with internet access. Their modus operandi includes bulk distribution of malicious payloads through malvertising, suggesting a high operational tempo and focus on maximizing the number of infections. Campaign patterns indicate a preference for rapid infection and immediate exfiltration, coupled with robust persistence mechanisms to maintain long-term access. Notable past operations include credential theft campaigns and cryptojacking events reported across Europe and North America, but specifics remain limited due to their relatively new emergence in April 2023.

IOC Patterns

  • Spear-phishing emails with malicious links or attachments
  • Malvertising-induced drive-by downloads
  • Payloads delivered via password-protected RAR files mimicking cracked software
  • DNS queries related to known x3d miner infrastructure
  • Registry changes and scheduled tasks indicative of persistence
  • Monero wallet addresses linked to known x3d miner accounts

Recommended Actions

  • Patch all systems regularly to mitigate potential vulnerabilities exploited by the malware.
  • Implement network monitoring for Indicators of Compromise (IOC) related to x3d miner campaigns.
  • Use endpoint detection and response (EDR) tools to identify and block known malicious file hashes.
  • Educate users to avoid clicking on suspicious links and downloading untrusted software.
  • Enforce strict policies against executing unknown files, especially those compressed in password-protected archives.
  • Monitor for unusual cryptocurrency transactions linked to the organization's systems.

Suggested Tags

Financially motivated
Malvertising
Cryptojacking
Spear-phishing
Vidar stealer
XMRig miner

Confidence Assessment

Moderate confidence in the data. The actor's operational methods are well-documented, but there is limited intelligence on long-term objectives beyond financial gain and specific campaign KPIs.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. threats.vega.io — Cited by web research for: MuddyWater
  2. unit42.paloaltonetworks.com — Cited by web research for: T1574.002
  3. www.infosecurity-magazine.com — Cited by web research for: phishing
  4. thehackernews.com — Cited by web research for: ClickFix
  5. feeds.podcastics.com — Cited by web research for: Anubis
  6. www.vulnu.com — Cited by web research for: RoundCube
  7. ministang.com — Cited by web research for: curl

Intel Summary

1

Techniques

49

Tools

0

Campaigns

40

IOCs

0

Observed Data

1

Tactics

Tags

Financial Targeting
Backdoor / C2
Data Exfiltration
Financially motivated
Malvertising
Cryptojacking
Spear-phishing
Vidar stealer
XMRig miner

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
55%
Added
Jul 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.