Skip to content
September 18, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Malware
  • Adware PBot upgrade to install cryptocurrency miner
  • Malware

Adware PBot upgrade to install cryptocurrency miner

Do Son June 29, 2018 3 minutes read
Add Daily CyberSecurity as a preferred source on Google

Anton V. Ivanov, a security researcher from Kaspersky Lab, said in a blog post published on Tuesday that they discovered the first version of the PBot (PythonBot) malicious adware more than a year ago. It was named because its core module writes in Python.

Since then, all versions that have appeared one after another have been procedurally modified to some degree, and one version seems to have gone beyond the scope of advertising software because it will install a crypto-money miner on the infected computer.

Ivanov pointed out that the other PBot versions they detected were limited to playing advertisements that were not expected to see on the web pages visited by the victims. Also, they initially tried to inject a malicious DLL into the browser. The difference is that the first version displays advertisements on web pages by running JS scripts, while the second version does not do so, it chose to install ad extensions in the browser.

The developers of PBot are more interested in the latter, they are continually making changes based on it, to release new variants, and confusing each option. Another unique feature of the second version of the Pbot modification is that it provides a module that can be used to update scripts and download new browser extensions.

In April of this year, researchers at Kaspersky Lab noted that there were more than 50,000 attempts to install PBot on the computers of their product users. And this number is still increasing, indicating that this adware is even being distributed. Among them, the most severely affected are Russia, Ukraine and Kazakhstan.

 

As malicious adware, the purpose of PBot is to redirect users to their sponsors’ websites by displaying advertisements, thereby bringing benefits to their developers. This is a relatively old way of making money, and it needs to survive from the browser vendor’s continuously improving ad-blocking technology.

Also, the developers of PBot also seem to be not very satisfied with the existing revenue. The rush of cryptocurrency has indeed attracted enough attention, not just investors but also cybercriminals. The crypto-money miners mentioned above have been proven to be able to mine Bitcoin and Litecoin. No surprise, PBot developers seem to want to take place in the industry of cryptocurrency mining.

In the end, it is worth proposing that no matter what version of PBot, it aims at running Windows computers. Given the popularity of Windows, we recommend that computer users should maintain good habits of using anti-virus products to avoid such malicious software.

Source, Image: securelist

Related coverage

  • Mocha Manakin: New Threat Group Uses “Paste and Run” to Deploy Custom NodeJS RAT!
  • “Webrat” Trap: Hackers Lure Junior Security Researchers with Fake GitHub Exploits
  • Stealth Attack: EarthKapre Leverages Cloud and DLL Sideloading for Data Exfiltration
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Stay Ahead of the Threat

Join security professionals receiving zero-hour CVE alerts, PoC updates, and threat analysis directly to their inbox.

No spam. One actionable email per week. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Adware PBot

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2025-39964CVSS 7.8
    In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg...
    CISA KEV📅 Added to KEV: Sep 18, 2026
  • CVE-2026-53266CVSS 8.8
    In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The...
    CISA KEV📅 Added to KEV: Sep 18, 2026
  • CVE-2026-76460CVSS 10.0
    A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to...
    Admin intelCISA KEV📅 Added to KEV: Sep 16, 2026📅 Updated: Sep 16, 2026
  • CVE-2026-89026CVSS 9.8
    The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT...
    Admin intel📅 Updated: Sep 16, 2026
  • CVE-2026-58704
    In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This...
    Admin intelCISA KEV📅 Added to KEV: Sep 16, 2026📅 Updated: Sep 16, 2026
  • CVE-2026-87886
    Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin...
    Admin intelCISA KEV📅 Added to KEV: Sep 16, 2026📅 Updated: Sep 16, 2026
  • CVE-2026-87827CVSS 10.0
    Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-78006CVSS 9.8
    The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to,...
    Admin intel📅 Updated: Sep 15, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-59163CVSS 9.1
    Mnemosyne is a memory layer for artificial intelligence agents. Prior to v3.10.1, the auth check in mnemosyne/core/sync_server.py parsed...
    📅 Updated: Sep 18, 2026
  • CVE-2026-92489CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix skb double-free in xfrm_dev_direct_output() A return...
    📅 Updated: Sep 18, 2026
  • CVE-2026-90414CVSS 9.1
    In the Linux kernel, the following vulnerability has been resolved: IB/isert: reject PDUs declaring more data than was...
    📅 Updated: Sep 18, 2026
  • CVE-2026-90413CVSS 9.1
    In the Linux kernel, the following vulnerability has been resolved: IB/isert: reject login PDUs declaring more data than...
    📅 Updated: Sep 18, 2026
  • CVE-2026-90235CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: sunrpc: xprtsock: annotate shared socket callbacks with READ_ONCE/WRITE_ONCE...
    📅 Updated: Sep 18, 2026
  • CVE-2026-90230CVSS 9.1
    In the Linux kernel, the following vulnerability has been resolved: nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate() nvmet_execute_auth_send()...
    📅 Updated: Sep 18, 2026
  • CVE-2026-90173CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: smb: smbdirect: free completion queues with ib_free_cq() smbdirect_connection_destroy_qp()...
    📅 Updated: Sep 18, 2026
  • CVE-2026-90151CVSS 9.8
    In the Linux kernel, the following vulnerability has been resolved: NFSv4: remove callback IDR entry on client allocation...
    📅 Updated: Sep 18, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.