Email auto-reply vulnerability allows hackers to mine cryptocurrency
Cybersecurity researchers have discovered a novel method used by hackers to deliver malware for stealthy crypto mining, leveraging automated email replies.
Researchers from the threat intelligence firm Facct reported that hackers exploited auto-reply emails from compromised accounts to target Russian companies, marketplaces and financial institutions.
Using this tactic, the attackers sought to install the XMRig miner on their victims’ devices to mine digital assets.
An example of an auto-reply letter with a link to malware Source: Habr
The security company said it had identified 150 emails containing XMRig since the end of May. However, the cybersecurity firm also said that its business email protection system blocked malicious emails sent to its clients.
The danger of auto-replies with malware
Facct senior analyst Dmitry Eremenko explained that the delivery method is dangerous because potential victims initiate the communications. With normal mass-delivered messages, the targets have the option to ignore emails that they deem irrelevant.
However, with the auto-replies, victims expect a response from the person they emailed first, not knowing that the email they are contacting is compromised. Eremenko said:
“In this case, although the letter does not look convincing, communication has already been established, and the file distribution may not arouse particular suspicion.”
The cybersecurity firm urged companies to conduct regular training to increase employees’ knowledge of cybersecurity and current threats. The firm also urged firms to use strong passwords and multifactor authentication mechanisms.
In a previous interview, ethical hacker Marwan Hachem told Cointelegraph that using different communications devices can also help with security. It isolates unwanted software and prevents hackers from reaching your main device.
Related: OpenAI’s press account hack was 5th security breach in 20 months
What is the XMRig?
The XMRig is a legitimate open-source application that mines the Monero ( XMR ) cryptocurrency. However, hackers have integrated the software into their attacks, using various tactics to install the app into different systems since 2020.
In June 2020, a malware called “Lucifer” targeted old vulnerabilities in Windows systems to install the XMRig mining application.
In August 2020, a malware botnet called “FritzFrog” was deployed to millions of IP addresses. The malware targeted government offices, educational institutions, banks and companies to install the XMRig app.
Magazine: Asia Express: WazirX hackers prepped 8 days before attack, swindlers fake fiat for USDT
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Web3 ai Could Lead 2025’s Best Cryptos With 1,747% ROI, Outshining Toncoin & Chainlink’s Performance
Toncoin (TON) and Chainlink (LINK) show strong market positions, but Web3 ai’s AI-driven platform and sub-$0.001 price point may offer greater potential for exponential growth.Toncoin (TON): Leveraging Telegram’s Ecosystem for GrowthChainlink (LINK): Technical Indicators Point to Potential BreakoutWeb3 ai: Affordable Entry with AI-Driven Security ToolsClosing Thought

Ethereum Set to Soar Past $4,000 Again
Ethereum eyes a comeback above $4,000 with a projected 55% surge amid rising market optimism.What’s Driving the Ethereum Rally?Could Ethereum Break Past Its All-Time High?

Lark Davis: Best Time to Make Money in Crypto
Crypto analyst Lark Davis says this is the best time to make money in crypto. Here’s why you should pay attention now.Why This Window Matters So MuchHow to Lock In for Maximum Gains

Top Rated Cryptos to Buy in 2025: BlockDAG, Tron, Polygon, and Polkadot Line Up Ahead of Q3 Shift
Explore the top rated cryptos to buy in 2025, featuring BlockDAG’s limited-time 'Double Your BDAG' offer, and why Tron, Polygon, and Polkadot are gaining strong attention this year1. BlockDAG (BDAG)2. Tron (TRX)3. Polygon (MATIC)4. Polkadot (DOT)Closing View on Key 2025 Contenders

Trending news
MoreCrypto prices
More








