Also known as: tracked as, MuddyWater, education, legal, insurance, technology, manufacturing, MERCURY, Storm-1175
A financially motivated campaign identified in April 2026 delivers Vidar stealer and XMRig cryptocurrency miner to victims worldwide through malvertising. Attackers distribute password-protected archives impersonating cracked software, using Go-compiled loaders built with the Factory-v3 framework. The malware employs sophisticated evasion techniques including rogue Authenticode certificates mimicking JustWatch and BleacherReport, file-size inflation to hundreds of MB with null bytes, and AMSI bypass. Once executed, Vidar stealer exfiltrates browser credentials, cookies and cryptocurrency wallets to C2 infrastructure, while XMRig mines Monero cryptocurrency. The operation establishes persistence through registry modifications, scheduled tasks and startup folder scripts. The threat actor, operating under the moniker X3D MINER, primarily targets victims in the U.S. and European Union through a dual-monetization scheme combining credential theft and cryptojacking.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
The x3d miner threat actor is a financially motivated group targeting individuals globally through malvertising campaigns. They deploy malware including Vidar stealer and XMRig cryptocurrency miner to steal credentials and hijack computing power for cryptojacking, primarily affecting users in the U.S. and European Union.
Goals & Targeting
The x3d miner's primary strategic objective is financial gain, achieved through two main revenue streams: credential theft for potential sale on darknet markets and cryptojacking to generate Monero cryptocurrency. The targeting focus on individuals likely reflects the ease of large-scale attacks through malvertising, as well as the higher value of targets in the U.S. and EU regions where cryptocurrency adoption is higher. Campaign activities indicate a preference for low-effort, high-yield tactics rather than nation-state espionage.
Enhanced Description
The x3d miner threat actor operates a financially motivated campaign identified in April 2026, delivering malware to victims worldwide through malvertising campaigns. The operation involves distributing password-protected archives impersonating cracked software, leveraging Go-compiled loaders developed with the Factory-v3 framework. These loaders employ sophisticated evasion techniques such as rogue Authenticode certificates mimicking legitimate services like JustWatch and BleacherReport. Additionally, the malware inflates file sizes to hundreds of MB using null bytes and bypasses AMSI detection mechanisms. Once executed, Vidar stealer exfiltrates sensitive information including browser credentials, cookies, and cryptocurrency wallets, while XMRig mines Monero cryptocurrency. The threat actors establish persistence through registry modifications, scheduled tasks, and startup folder scripts. The group primarily targets individuals in the United States and European Union regions, utilizing a dual-moniatization approach combining credential theft and cryptojacking activities.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The x3d miner threat actors operate a persistent campaign targeting mainly consumers and businesses with internet access. Their modus operandi includes bulk distribution of malicious payloads through malvertising, suggesting a high operational tempo and focus on maximizing the number of infections. Campaign patterns indicate a preference for rapid infection and immediate exfiltration, coupled with robust persistence mechanisms to maintain long-term access. Notable past operations include credential theft campaigns and cryptojacking events reported across Europe and North America, but specifics remain limited due to their relatively new emergence in April 2023.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in the data. The actor's operational methods are well-documented, but there is limited intelligence on long-term objectives beyond financial gain and specific campaign KPIs.
No campaigns linked yet.
No observed data linked yet.
1
Techniques
49
Tools
0
Campaigns
40
IOCs
0
Observed Data
1
Tactics