Cryptomining Campaign Used Obfuscated File Payloads

A new malicious campaign has been discovered deploying XMRig miners by hiding payloads in images, audio, and DNS records.

Updated on Sept. 19, 2026 in Cybersecurity

Isometric editorial illustration of storage volumes and fragmenting geometric shards, representing a sophisticated cybersecurity malware campaign.
Security researchers have uncovered a sophisticated cryptomining campaign using steganography to hide malicious XMRig payloads within common image and audio files. AI Illustration. Upload story photo >

Live Poll

Do you feel your personal digital devices are adequately protected from modern malware and cyber threats?

Security researchers have identified a sophisticated cryptomining campaign that utilizes XMRig miners to hijack system resources. The malware conceals its malicious payloads within Windows Registry entries, DNS TXT records, PNG images, and WAV audio files.

Why it matters

This campaign demonstrates an evolving strategy of steganography and obfuscation used to bypass standard security detection measures. By embedding payloads in common file types, attackers can maintain persistent access and carry out unauthorized mining operations undetected.

The malware executes via an initial PowerShell command that retrieves hidden payloads from obfuscated registry keys and media files. This method enables the XMRig software to run unauthorized cryptocurrency mining operations.

The players

XMRig

XMRig is a high-performance, open-source cryptocurrency miner often leveraged by malicious actors to exploit compromised hardware for financial gain.

The details

Security teams uncovered the campaign following a series of repeated PowerShell activity alerts. The malware relies on multi-stage obfuscation, forcing the system to reassemble malicious components from disparate locations to execute the mining software.

Timeline

  1. September 19, 2026: The discovery of the cryptomining campaign was formally reported.

The Big Picture

The use of the XMRig cryptocurrency miner in this campaign marks a continuation of utilizing legitimate open-source mining tools for illicit distributed computing schemes.

Users may experience unexplained system sluggishness or spikes in hardware resource consumption as the miner operates in the background. Individuals should monitor PowerShell activity and ensure security software is configured to detect obfuscated file signatures.

The takeaway

Organizations should implement strict monitoring for irregular PowerShell execution to identify obfuscated malware components. Maintaining updated security protocols is essential to prevent the hidden execution of unauthorized background processes.

Further reading

For more information on emerging threats, visit our Cybersecurity section.

Live Poll

Do you feel your personal digital devices are adequately protected from modern malware and cyber threats?