<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cryptomining on HackingPassion.com : root@HackingPassion.com-[~]</title><link>https://hackingpassion.com/tags/cryptomining/</link><description>Recent content in Cryptomining on HackingPassion.com : root@HackingPassion.com-[~]</description><generator>Hugo</generator><language>en</language><lastBuildDate>Sun, 20 Sep 2026 15:33:32 +0200</lastBuildDate><atom:link href="https://hackingpassion.com/tags/cryptomining/index.xml" rel="self" type="application/rss+xml"/><item><title>PowerShell Malware Hid in the Registry and Pulled Its Miner Out of DNS Records a PNG and Four WAV Files</title><link>https://hackingpassion.com/powershell-registry-dns-png-wav-xmrig-miner/</link><pubDate>Sun, 20 Sep 2026 15:33:32 +0200</pubDate><guid>https://hackingpassion.com/powershell-registry-dns-png-wav-xmrig-miner/</guid><description>&lt;p>&lt;strong>Your Windows PC mined Monero on 40 percent of your threads. A scan of the disk found nothing to delete. The code sat in the registry. The rest arrived in DNS records, a PNG image and four WAV files.&lt;/strong>&lt;/p>
&lt;p>The machine would not stop complaining about PowerShell. Clean it up, and the next day the alerts were back. The startup folder was empty. There was no download to point at and the fans kept running anyway.&lt;/p></description></item></channel></rss>