Skip to content
October 10, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Malware
  • Adware PBot upgrade to install cryptocurrency miner
  • Malware

Adware PBot upgrade to install cryptocurrency miner

Do Son June 29, 2018 3 minutes read
Add Daily CyberSecurity as a preferred source on Google

Anton V. Ivanov, a security researcher from Kaspersky Lab, said in a blog post published on Tuesday that they discovered the first version of the PBot (PythonBot) malicious adware more than a year ago. It was named because its core module writes in Python.

Since then, all versions that have appeared one after another have been procedurally modified to some degree, and one version seems to have gone beyond the scope of advertising software because it will install a crypto-money miner on the infected computer.

Ivanov pointed out that the other PBot versions they detected were limited to playing advertisements that were not expected to see on the web pages visited by the victims. Also, they initially tried to inject a malicious DLL into the browser. The difference is that the first version displays advertisements on web pages by running JS scripts, while the second version does not do so, it chose to install ad extensions in the browser.

The developers of PBot are more interested in the latter, they are continually making changes based on it, to release new variants, and confusing each option. Another unique feature of the second version of the Pbot modification is that it provides a module that can be used to update scripts and download new browser extensions.

In April of this year, researchers at Kaspersky Lab noted that there were more than 50,000 attempts to install PBot on the computers of their product users. And this number is still increasing, indicating that this adware is even being distributed. Among them, the most severely affected are Russia, Ukraine and Kazakhstan.

 

As malicious adware, the purpose of PBot is to redirect users to their sponsors’ websites by displaying advertisements, thereby bringing benefits to their developers. This is a relatively old way of making money, and it needs to survive from the browser vendor’s continuously improving ad-blocking technology.

Also, the developers of PBot also seem to be not very satisfied with the existing revenue. The rush of cryptocurrency has indeed attracted enough attention, not just investors but also cybercriminals. The crypto-money miners mentioned above have been proven to be able to mine Bitcoin and Litecoin. No surprise, PBot developers seem to want to take place in the industry of cryptocurrency mining.

In the end, it is worth proposing that no matter what version of PBot, it aims at running Windows computers. Given the popularity of Windows, we recommend that computer users should maintain good habits of using anti-virus products to avoid such malicious software.

Source, Image: securelist

Related coverage

  • Sophisticated Campaign Targets Manufacturing Industry with Lumma Stealer and Amadey Bot
  • Amatera Password Stealer Abuses Service Workers and Smart Contracts
  • North Korea’s Cyber Shadow War: Unmasking RustBucket and KandyKorn
  • ‘Trojanized’ npm Package Targets Cryptocurrency Wallets, Steals USDT
  • RedisRaider Worm Exploits Misconfigured Redis for Cryptojacking
  • Military-Grade ValleyRAT Goes Rogue: Kernel Rootkit Builder Leak Triggers Massive Global Surge
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.

We respect your inbox. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Adware PBot

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-102255CVSS 10.0
    A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access...
    Admin intel📅 Updated: Oct 9, 2026
  • CVE-2026-105133CVSS 6.9
    A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the function checkSysPwd of the file...
    Admin intel📅 Updated: Oct 9, 2026
  • CVE-2023-22894CVSS 4.9
    Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2016-3081CVSS 8.1
    Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled,...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2015-3306CVSS 10.0
    The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2015-5477CVSS 7.5
    named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2021-3199CVSS 9.8
    Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2026-94504CVSS 7.2
    Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the...
    Admin intel📅 Updated: Oct 7, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-108551CVSS 9.3
    openapi-typescript-codegen through 0.31.0 contains a code injection vulnerability that allows attackers controlling an OpenAPI document to inject JavaScript...
    📅 Updated: Oct 10, 2026
  • CVE-2026-108549CVSS 9.2
    cc-connect through 1.5.0 contains a missing authentication vulnerability in the MAX platform adapter webhook mode in platform/max/max.go that...
    📅 Updated: Oct 10, 2026
  • CVE-2026-84272CVSS 9.8
    IBM Guardium Data Protection 12.1 and 12.2.2 are vulnerable to missing authentication in the edge-controller component. An unauthenticated...
    📅 Updated: Oct 10, 2026
  • CVE-2026-19491CVSS 9.1
    IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a...
    📅 Updated: Oct 10, 2026
  • CVE-2026-78401CVSS 9.8
    IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a...
    📅 Updated: Oct 10, 2026
  • CVE-2026-14991CVSS 9.8
    IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable...
    📅 Updated: Oct 10, 2026
  • CVE-2026-16916CVSS 9.1
    IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a...
    📅 Updated: Oct 10, 2026
  • CVE-2026-93945CVSS 9.8
    Deserialization of Untrusted Data vulnerability in Axiomthemes Balance balance allows Object Injection.This issue affects Balance: from n/a through...
    📅 Updated: Oct 10, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.