Librarian Ghouls hacker group targeting Russians to mine crypto
2025-06-11 15:03:46 Primitive Reading

 

The Librarian Ghouls hacker group has compromised hundreds of Russian devices and used them to mine crypto in an apparent case of cryptojacking, cybersecurity firm Kaspersky says.

The hacker group, which is also known as Rare Werewolf, gains access to systems through malware-ridden phishing emails disguised as messages from legitimate organizations that appear to be official documents or payment orders, Kaspersky said in a report on Monday.

  Bad actors can gain access to devices to steal resources such as computing power and mine crypto. Source: Cointelegraph


Hackers scope out device info before mining

After a computer is infected with the malware, the hackers establish a remote connection and disable security systems such as Windows Defender.

The infected device is also programmed to turn on at 1 am and shut down at 5 am, with the hackers using the time frame to further establish unauthorized remote access and steal login credentials.

“It is our assessment that the attackers use this technique to cover their tracks so that the user remains unaware that their device has been hijacked,” Kaspersky said.

They then steal login credentials and also collect information about the device’s available RAM, CPU cores and GPUs to optimally configure the crypto miner before deploying it.

While the miner is running, the hackers maintain a connection to the mining pool, sending a request every 60 seconds, according to Kaspersky.

“We observe that the attackers are continuously refining their tactics, encompassing not only data exfiltration but also the deployment of remote access tools and the use of phishing sites for email account compromise,” the firm said.

Cryptojacking campaign ongoing since 2024

So far, the hacking campaign, which started in December and is ongoing, has affected hundreds of Russian users, particularly industrial enterprises and engineering schools, with additional victims reported in Belarus and Kazakhstan.

The origin of the group hasn’t been established; however, Kaspersky said the phishing emails are “composed in Russian and include archives with Russian filenames, along with Russian-language decoy documents.”

“This suggests that the primary targets of this campaign are likely based in Russia or speak Russian,” Kaspersky said.

Disclaimer: This specification is preliminary and is subject to change at any time without notice. Amazon Finance assumes no responsibility for any errors contained herein.

Recommended reading
Strategy Shifts Capital Raise to Preferred Stocks as Common Share Issuance Loses Allure

10-22     admin     10647 Reading

Riot Sells $1.58M of Bitfarms Shares as Part of Investment Review

10-22     admin     7135 Reading

BlockX.VC Makes Strategic Investment in TronBank.Pro to Boost TRON Ecosystem Financial Infrastructure

10-22     admin     7099 Reading

Corruption watchdog clears Javier Milei over LIBRA crypto scandal

10-22     admin     15082 Reading

Coinbase CEO says unnecessary account freezes cut by 82%

10-22     admin     9273 Reading

Singapore’s ousted crypto firms may not find shelter elsewhere

10-22     admin     12795 Reading

10 signs an airdrop is a scam — and how to stay safe

10-22     admin     14021 Reading

Amazon to Spend $10 Billion on North Carolina Data Centers for AI Expansion

10-22     admin     12742 Reading

SEC wins $1.1M as alleged crypto conman a no-show in court

10-22     admin     13135 Reading

South Korea’s new president will bolster crypto, but scandals prevail

10-22     admin     13357 Reading

Crypto leverage trader James Wynn loses $25M on Bitcoin bet

10-22     admin     11685 Reading

Trump memecoin wallet in ‘absolute chaos’ as family org unaware of launch

10-22     admin     10109 Reading

Bitcoin’s shrinking supply may trigger price breakout: Sygnum

10-22     admin     9427 Reading

Bitcoin on ‘very shaky ground’ as new BTC price top nears: Ammous

10-22     admin     13512 Reading

Corporate Bitcoin treasuries control over 3% of total BTC supply

10-22     admin     12533 Reading