New Crypto-Mining Malware Targeting Asian Firms With NSA Tools
A new form of malware discovered by Symantec is targeting enterprises using leaked NSA tools to infect networks and mine monero.

A new form of malware is targeting enterprises in Asia to mine monero
Cybersecurity software provider Symantec published the news in a blog post Wednesday, saying that over 80 percent of victims are located in China, with nations such as South Korea, Japan and Vietnam also seeing activity.
Dubbed "Beapy," the malicious code is a file-based crypto miner, not a browser-based one, the firm said. It works by sending a malicious Excel file to victims as an email attachment, downloading the DoublePulsar backdoor onto the victim’s system if the file is opened.
DoublePulsar (notably developed by the U.S. National Security Agency before it was stolen then released to the public in 2017) was also used in the WannaCry ransomware attack in 2017, according to the post.
Once DoublePulsar is installed on to a victim’s machine, the miner is downloaded. At the same time, it uses another leaked NSA tool, EternalBlue, to propagate across the infected network via unpatched computers where it can steal credentials to further access patched machines.
Cryptojacking malware can have a major impact on enterprises, Symantec said, including slowing down device performance, reducing employee productivity and increasing costs.
Although cryptojacking activity has decreased by about 52 percent over the last year, it is still an area of interest among hackers which largely target businesses.
Symantec said:
“Looking at the overall figures for cryptojacking, we can see that there were just under 3 million cryptojacking attempts in March 2019. While a big drop from the peak of February 2018, when there were 8 million cryptojacking attempts, it is still a significant figure.”
The firm said it first noticed Beapy in January of this year, but activity has increased since early March.
Monero's privacy features make it by far the most popular cryptocurrency among hackers deploying mining malware. A recent academic study estimated that cybercriminals have mined around 5 percent of the total monero in circulation.
Earlier this year, researchers at cybersecurity firm Palo Alto Networks discovered a form of malware that takes administrative control to first uninstall cloud security products and then injects code to mine monero. The same team also discovered another variant that steals browser cookies and other information on Apple Mac computers to directly steal cryptocurrencies.
Symantec image via Shutterstock
More For You
KuCoin Hits Record Market Share as 2025 Volumes Outpace Crypto Market

KuCoin captured a record share of centralised exchange volume in 2025, with more than $1.25tn traded as its volumes grew faster than the wider crypto market.
What to know:
- KuCoin recorded over $1.25 trillion in total trading volume in 2025, equivalent to an average of roughly $114 billion per month, marking its strongest year on record.
- This performance translated into an all-time high share of centralised exchange volume, as KuCoin’s activity expanded faster than aggregate CEX volumes, which slowed during periods of lower market volatility.
- Spot and derivatives volumes were evenly split, each exceeding $500 billion for the year, signalling broad-based usage rather than reliance on a single product line.
- Altcoins accounted for the majority of trading activity, reinforcing KuCoin’s role as a primary liquidity venue beyond BTC and ETH at a time when majors saw more muted turnover.
- Even as overall crypto volumes softened mid-year, KuCoin maintained elevated baseline activity, indicating structurally higher user engagement rather than short-lived volume spikes.
More For You
Bitcoin hash rate slides during U.S. winter storm while markets shrug off mining disruption

The temporary loss of mining power underscores academic concerns that geographic and pool concentration can magnify infrastructure failures, though markets showed little immediate reaction.
What to know:
- Bitcoin’s hashrate fell about 10 percent during a U.S. winter storm, underscoring how local power disruptions can strain the network’s capacity to process transactions.
- Researchers have shown that concentrated mining, as seen in a 2021 regional outage in China, can lead to slower block times, higher fees and broader market disruptions.
- With a few large pools now controlling most of Bitcoin’s hashrate, the network is increasingly vulnerable to localized infrastructure failures, even as the price of BTC remains largely unaffected in the short term.











