Hackers Exploit Windows Tool to Deploy Crypto-Mining Malware

Mining
Author
Last updated: 
Source: AdobeStock / Tomasz Bidermann

Hackers have targeted a popular Windows-based software packaging tool to infect computers with crypto mining malware, IT security firm Cisco Talos Intelligence Group has revealed.

The mining attack on computers happens through a Windows tool known as Advanced Installer, and the attackers have used the tool to package malicious code together with software installers from popular tools like Adobe Illustrator, Autodesk 3ds Max and SketchUp Pro.

The software tools affected are used specifically for 3-D modeling and graphic design, and mainly use the French language, the firm said.

Infected software installers. Source: Cisco Talos Intelligence Group

Cisco Talos’ report explained that once infected, the computers, which are often used by graphic designers and therefore have powerful Graphics Processing Units (GPU), are then used to mine crypto on behalf of the attacker.

“The campaign likely affects business verticals such as architecture, engineering, construction, manufacturing and entertainment, as the attackers use software installers specifically created for 3-D modeling and graphic design,” the report said.

It added that these industries are attractive targets for the hackers because powerful GPUs are highly useful for mining various cryptocurrencies.

Once infected, the computers start running the M3_Mini_Rat tool, which allows attackers to download and run the Ethereum malware miner PhoenixMiner and the multi-coin mining malware lolMiner.

Among the most popular proof-of-work (PoW) cryptocurrencies that can be mined with GPUs today is the Ethereum fork Ethereum Classic (ETC) and the privacy-focused coin Monero (XMR).

Bitcoin (BTC) is generally mined on more specialized mining machines known as ASICs.

The firm said the activity has been ongoing since “at least November 2021,” and victims are spread out around the world but with a concentration in France and other French-speaking regions.

Source: Cisco Talos Intelligence Group

2M+

Active Monthly Users Around the World

250+

Guides and Reviews Articles

8

Years on the Market

70

International Team Authors
editors
+72 More
At Cryptonews, we aim to make cryptocurrency, blockchain, and Web3 understandable, and information available to everyone, no matter what level you are in your investment journey. Founded in 2017, Cryptonews has been dedicated to delivering reliable, multilingual coverage of the cryptocurrency industry.

Best Crypto ICOs

Discover trending tokens still in presale — early-stage picks with potential.

Explore Our Tools

Smart tools made for everyday crypto users

Market Overview

  • 7d
  • 1m
  • 1y
Market Cap
$3,245,403,663,961
+1.22%
Trending Crypto

More Articles

Blockchain News
Optimism Proposes Using Half Its Revenue to Buy Back OP Tokens
Anas Hassan
Anas Hassan
2026-01-08 20:56:09
Price Analysis
Shiba Inu Price Prediction: SHIB is Up 25% in January – How High Can it Go This Week?
Simon Chandler
Simon Chandler
2026-01-08 18:29:49
Crypto News in numbers
editors
Authors List + 66 More
2M+
Active Monthly Users Around the World
250+
Guides and Reviews Articles
8
Years on the Market
70
International Team Authors