Fake Pirated Software Ads Are Draining Passwords and Hijacking Computers to Mine Crypto

A campaign uncovered by Palo Alto Networks researchers tricks people into downloading malware disguised as cracked software, stealing saved passwords while quietly running up victims' electricity bills.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: A cluttered small-business office desk at night
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Palo Alto Networks' Unit 42 researchers discovered the campaign in April 2025 and published their findings on 7 July 2026.
  • The malware drops two payloads: Vidar, which steals saved browser passwords and crypto wallet files, and XMRig, which secretly uses the victim's computer to generate Monero cryptocurrency for the criminals.
  • Researchers observed 43 separate malware samples carrying 27 unique internal identifiers, a trick that makes standard antivirus detection unreliable.
  • Unit 42 published indicators of compromise, meaning specific file signatures and server addresses, that defenders can use to check for infection.

Someone searching for free, unlicensed software clicks an online advert. It looks ordinary. It takes them to a page offering what appears to be a cracked installer for paid software. They download a password-protected archive, enter the password shown on the page, and two pieces of malware quietly install themselves.

This is the attack Unit 42 threat researchers Bharath Nannaka and Pranay Kumar Chhaparwal documented earlier this month, first reported by Dark Reading. The campaign uses malvertising, criminals paying for real advertising slots to deliver malicious downloads, to reach victims at scale. It primarily targets consumers and small to mid-size businesses in the United States and Europe. We covered a related malvertising chain on 4 June 2026 when Unit 42 traced a backdoor hidden inside Flutter-built Mac apps to ad clicks; the monetisation logic here is more aggressive because the same infection does two jobs at once.

How does the malware actually make money for the criminals?

Two ways, running simultaneously.

Vidar is an infostealer, software designed to quietly copy data off your device. It pulls saved passwords, browser cookies (the small files that keep you logged into websites), browsing history, autofill data, and crypto wallet files. Criminals sell that haul on underground markets. "The operator behind this campaign runs a dual-monetization scheme," Nannaka and Chhaparwal wrote in their report. "Criminals sell credentials and session cookies stolen by Vidar stealer on criminal log markets, while XMRig provides passive income from hijacked victim CPU cycles."

XMRig is an open-source cryptominer that uses your processor to solve calculations that generate Monero, a privacy-focused cryptocurrency, for whoever controls it. Victims typically notice a slow machine or a creeping electricity bill. The criminals spend nothing on hardware.

The password on the downloaded archive stops automated security scanners from opening the file before a human does. It's a deliberate choice, not an accident.

Should you worry about your antivirus catching this?

Probably not reliably. The loader is built on a framework called Factory-v3 and generates a slightly different version for each victim. Unit 42 found 27 distinct internal build identifiers across 43 samples, which defeats tools that rely on recognising a known file fingerprint.

The loader is also padded with meaningless data to push its file size toward 500 megabytes. Many automated analysis tools skip large files, and most small businesses never adjust that threshold. It also carries a fake code-signing certificate, a digital stamp meant to signal official approval, bearing the name of JustWatch, a legitimate streaming-guide service. Denis Calderone, principal and CTO of Suzu Labs, told Dark Reading the evasion tactics are "specifically tuned for SMB-grade defenses."

Once installed, the malware adds itself to the Windows Registry's Run keys and creates scheduled tasks so it restarts on every reboot.

What affected users should do. If you recently downloaded software from an unofficial source, run a full scan with updated antivirus software. Change passwords stored in your browser and enable two-factor authentication (a second login step, usually a code sent to your phone) wherever you can. Block outbound connections to pool.supportxmr[.]com at the network level. Unit 42's full list of file hashes, server addresses and file paths is in the published report.

© 2026 Threat Vectr