Jump to content
Sign in to follow this  

Modified video games on Russian forum tainted with WaterMiner cryptominer

Recommended Posts



A Russian hacker with a knack for modifying popular video games implanted a stealth cryptominer in his creations, including a mod of Grand Theft Auto (GTA) that was recently found on a Russian-speaking forum, available for download.

The malware, known as WaterMiner, is also a mod – in this case, an altered version of a legit open-source miner known as XMRig, according to a Tuesday blog post from Minerva researchers, who shared their findings in advance with SC Media.

Omri Moyal, co-founder and vice president of research at Minerva Labs, said in an interview that the author of the GTA mod and the WaterMiner variant of XMRig are most likely same – a man with the alias "Martin Opc0d3r." Moyal said Opc0d3r left behind certain "breadcrumbs" in his coding that strongly suggest that he's responsible for both mods, noting that the underlying skills needed to crack a video game are "not much different" than required to author malware.

By embedding his cryptominer within modified video games, Opc0d3r is essentially sapping gamers of their computer processing power, using those stolen resources to secretly mine Monero cryptocurrency on the hacker's behalf.

To avoid possible detection, the XMRig was purposefully modified to watch out for any open windows running Windows Task Manager or similar utilities apps that help users determine which active programs are slowing down their machines. When such an app is opened, the mining activity immediately stops. Previous campaigns by the same actor employed malware variants that detected task monitoring apps in a different fashion – by inspecting a machine's running process list.

"It shows the advancement of cryptominers and how they might be used in the future," said Moyal.

  For More Details

   B2B Digital Advertising

Share this post

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
Sign in to follow this