Cryptocurrency boom fuels 2017 cybercrime surge
Abuse.ch reports a 2017 surge in cryptomining malware, Bitcoin-demanding extortion, and crypto-investment spam scams tied to rising coin prices.
This is a retrospective trend piece from abuse.ch reviewing how the 2017 cryptocurrency price boom shaped cybercriminal activity. The author notes that Bitcoin remains the preferred ransom currency for DDoS extortion groups (DD4BC, Armada Collective) and ransomware families (Crypt0L0cker, Locky, Cerber), and illustrates how the rising BTC price effectively multiplied the value of unclaimed ransom payments over time.
Separately, the researcher observed a sharp rise in cryptocurrency-mining malware samples starting mid-2017, growing from near zero to roughly 1,200 samples per month. These CoinMiners (e.g., XMRig, noobLoader) are frequently delivered as secondary payloads by droppers/loaders such as Smoke Loader and Neutrino, often bundled alongside banking trojans like Gozi, Citadel, and PandaZeuS — meaning infected machines are commonly compromised by multiple malware families simultaneously.
The article also documents a Swiss-focused spam campaign promoting fraudulent cryptocurrency trading platforms (thecryptosoftware.co, kryptohandel.trade, universemarkets.com) using snowshoe spam techniques from South African-hosted /24 netblocks, impersonating a fake entity called 'Internet Trends 2018' to lure victims into likely pyramid-scheme investment sites. Overall the piece is an informational trend summary rather than a report of a novel active threat.
Mentioned in this report
Source reporting: https://abuse.ch/blog/cybercriminals-taking-advantage-of-cryptocurrency-boom
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free