Monero-Mining Malware 'Crackonosh' Has Infected 222K Computers, Researchers Find

The virus has yielded over $2 million worth of XMR for its authors, security firm Avast said in a Thursday report.

AccessTimeIconJun 24, 2021 at 7:24 p.m. UTC
Updated Aug 21, 2021 at 6:59 p.m. UTC

Presented By Icon

Election 2024 coverage presented by

Stand with crypto

Malware called "Crackonosh" has been found in 222,000 compromised computers that were used to download illegal, torrented versions of popular video games, including "NBA 2K19" and "Grand Theft Auto V," according to a report from security company Avast published Thursday.

The virus, which has been circulating since at least June 2018, installs crypto-mining software that has yielded its authors over $2 million worth of monero.

  • Bitcoin Mining in the U.S. Will Become 'a Lot More Decentralized': Core Scientific CEO
    13:18
    Bitcoin Mining in the U.S. Will Become 'a Lot More Decentralized': Core Scientific CEO
  • Binance to Discontinue Its Nigerian Naira Services After Government Scrutiny
    05:10
    Binance to Discontinue Its Nigerian Naira Services After Government Scrutiny
  • The first video of the year 2024
    04:07
    The first video of the year 2024
  • The last regression video of the year 3.67.0
    40:07
    The last regression video of the year 3.67.0
  • Monero is a privacy coin that is often used by cybercriminals because it is much more difficult to trace than other cryptocurrencies like bitcoin. Monero-focused crypto-mining attacks are relatively common: The Pirate Bay, a website where users can download movies, music, software and games, announced in 2018 it would be “cryptojacking” visitors’ processing power to mine for monero, and in 2020, a botnet called “Vollgar” was found to be targeting Microsoft’s SQL servers to mine for monero, as well.

    According to Avast’s analysis, Crackonosh successfully operated for years because it had built-in mechanisms to disable security software and updates, which made it difficult for users to detect and remove the program. 

    The malware is thought to have originated in the Czech Republic, but it has a global reach. Cases in the United States make up only 5% of the total.

    Avast’s blog post addresses the spread of the malware and teaches affected users how to uninstall the program.

    The blog’s author, Daniel Benes, also shares some words of wisdom:

    “The key take-away from this is that you really can’t get something for nothing and when you try to steal software, odds are someone is trying to steal from you.”

    Disclosure

    Please note that our privacy policy, terms of use, cookies, and do not sell my personal information have been updated.

    CoinDesk is an award-winning media outlet that covers the cryptocurrency industry. Its journalists abide by a strict set of editorial policies. CoinDesk has adopted a set of principles aimed at ensuring the integrity, editorial independence and freedom from bias of its publications. CoinDesk is part of the Bullish group, which owns and invests in digital asset businesses and digital assets. CoinDesk employees, including journalists, may receive Bullish group equity-based compensation. Bullish was incubated by technology investor Block.one.


    Learn more about Consensus 2024, CoinDesk's longest-running and most influential event that brings together all sides of crypto, blockchain and Web3. Head to consensus.coindesk.com to register and buy your pass now.