Security researchers from Kaspersky and Securelist identified a major campaign in early 2025 targeting users—particularly in Russia—by disguising the miner as tools for bypassing internet restrictions (DPI bypass tools).

The miner is programmed to automatically pause mining activities if the user opens specific resource-monitoring programs (like Task Manager).

The file "Silent.Crypto.Miner.Builder.rar" is a malicious archive containing , a stealthy Trojan designed to hijack system resources for unauthorized cryptocurrency mining . Recent Distribution Campaigns