A miner infection is now also a foothold. The same fake update lure that used to drop a SilentCryptoMiner payload now brings in a RAT module, so a cleanup that only removes the miner can leave an attacker with continued access.
The lure is simple and broad. A fake player-update prompt on pirate streaming sites leads users to a ZIP that contains a legitimate installer and a malicious DLL; the installer trusts the DLL beside it and runs the attacker’s code inside a normal process. Kaspersky says the delivery pattern has stayed essentially the same and appears active in April 2026, with the campaign traceable back to at least 2022.
That shifts the risk from commodity cryptomining to persistent remote intrusion on consumer and managed endpoints alike. If users can reach pirated streaming or download sites, the infection path does not need email, and the compromise can survive the obvious cleanup.