Skip to main content

Hackers modify ransomware to deliver a Coinhive cryptocurrency-mining payload

Trend Micro recently discovered that hackers repurposed the XiaoBa ransomware to carry a cryptocurrency miner payload. Typically, XiaoBa infects a PC, encrypts its files, and holds those files hostage until the victim delivers a payment to hackers. But in this case, the new payload injects the Coinhive mining script into HTM and HTML files used by the infected PC. 

Coinhive is a JavaScript-based component that is injected into webpages. It uses a visiting PC’s processor to mine digital coins in the background although computers take a noticeable performance hit during the process. Typically, the mining ends once you leave the Coinhive-infested page, bringing your processor’s performance back up to speed. But Coinhive can also secretly reside in browser extensions, making an escape from the grueling process impossible while the browser remains open. 

Recommended Videos

The new XiaoBa variant appears to have a worm-style component, meaning it could spread from PC to PC connected to a local network, thus increasing the hackers’ financial gains. But that is not the worst-case scenario: This variant is also highly destructive. The revised code infects legitimate binary files (exe, com, scr, pif) to deliver the payload but destroys these files in the process. 

Please enable Javascript to view this content

“The malware will prepend itself to any file with the above extension,” the security firm states. “That is the only criteria checked before infection, unlike other malware that typically look for certain conditions or markers before infecting the file. It also traverses all directories. It will not avoid critical system files and can render the system critically unstable if it is not dealt with properly.” 

Trend Micro says the malware infects files of all sizes and does not leave any markers on the infected file, allowing for multiple infections — 10 as shown in one example — on a single PC. Thus, not only is the processor bogged down from the mining aspect, but the “stacked” infections consume large amounts of memory and likely a big chunk of disk space, too. 

Trend Micro currently knows of only two versions of the XiaoBa variant, both of which carry the Coinhive payload. Both will disable Windows User Account Control notifications while only one deletes Norton Ghost images, disk media images (ISO), and blocks access to anti-virus and forensic-related websites. Presumably, both inject the Coinhive script into webpages as they are downloaded and cached locally on the PC’s storage device. 

What is not clear is how PCs obtain the XiaoBa variants in the first place. Malware is typically spread through email and social network scams, requiring victims to click a link that downloads the malicious file. According to Trend Micro, one of the two variants propagates by using removable drives, like a USB-based storage stick.  

XiaoBa was first reported by MalwareHunter Team at the end of 2017. Once it lands on a PC, it disguises itself as system files, disables the firewall, and blocks security-focused websites. It also modifies the PC’s registry and allows other viruses to infect the system. That doesn’t even cover the ransomware aspect, which encrypts files until victims pay a ransom. 

Kevin Parrish
Former Digital Trends Contributor
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
One of the most exciting upcoming CES 2025 launches just got leaked
lenovo foldable laptop extended.

Last year, Lenovo teased a rollable laptop at MWC 2023, but it was purely a prototype. Now, a leak covered by The Verge from Evan Blass claims that the concept is becoming a reality and will be released at CES 2025 in just a few weeks.

The concept Lenovo laptop from last year looks like a completely normal laptop at first, but once you press a button on the side, more screen literally starts rolling out from under the keyboard. The screen slowly grows until you have basically two laptop screens stacked on top of each other.

Read more
ChatGPT just got a bump to its coding powers
ChatGPT collaborating with Notion

For its penultimate 12 Days of OpenAI announcement, the company revealed a trio of updates to ChatGPT's app integration on Thursday, which should make using the AI in conjunction with other programs on your desktop less of a chore.

OpenAI unveiled ChatGPT's ability to collaborate with select developer-focused macOS apps, specifically VS Code, Xcode, TextEdit, Terminal, and iTerm2, back in November. Rather than needing to copy and paste code into ChatGPT, this feature allows the chatbot to pull specified content from the coding app as you enter your text prompt. ChatGPT, however, cannot generate code directly into the app, as Cursor or GitHub Copilot are able to.

Read more
Here’s why some PC gamers shouldn’t install the latest Windows 11 update
Overwatch 2 running on the LG OLED 27 gaming monitor.

The latest Windows 11 update, codenamed 24H2, has been a troubled rollout for Microsoft, but one thing's been clear from the beginning: PC gamers should wait to install it. Let's add another issue to the list, shall we?

As spotted by Windows Latest, Microsoft has confirmed in an update to its Windows 11 24H2 problems page, that Windows 11 24H2 is causing issues with its Auto HDR feature. The result of the bug is that incorrect colors are being displayed or, even worse, are breaking games entirely and causing them to not be responsive.

Read more