Users of Kodi Media Player Targeted by Cryptomining Malware

Users of Kodi Media Player Targeted by Cryptomining Malware

Third-party add-ons were found to contain malware targeting Windows and Linux users

Users of the Kodi, beware! ESET researchers reported Thursday that they had found multiple add-ons for the popular media player containing malware designed to force users’ systems to mine cryptocurrency.

Kodi is a free downloadable media player intended for use with TVs, but does not stream any content on its own, relying on add-ons such as “Gaia” and “XvBMC” to provide content. These two, along with another popular repository called “Bubbles,” were the first three add-ons discovered to be infected with the malware.

All three of these repositories are currently offline, having been subject to copyright complaints, due to the prevalence of their use, and by extension Kodi’s, to stream pirated content. The malware purportedly takes advantage of the update verification system to “fingerprint” a user’s Operating System, and later uses this back door to install a coinminer, malware that uses the victim’s CPU to mine for cryptocurrency.

Nadav Avital, threat researcher at Imperva, a cybersecurity company, said that cyber criminals targeting Kodi isn’t surprising. “Cyber criminals are always looking to expand their target cycle in order to make more money,” Avital said. “In the past, we've seen rogue crypto miner malware infecting browsers, databases, management systems, cache systems and more.”

The criminals’ efforts were to mine the cryptocurrency Monero, and data obtained by ESET led them to believe they had infected at least 4,700 systems, and mined almost $7,000 worth of Monero. Most of the affected systems are in the United States, by far the region where Kodi’s user base is the largest.

This is actually the second incident of its kind, with the first malware campaign being discovered in 2017. In that instance, Kodi users found their systems unwittingly recruited into helping with DDoS (Distributed Denial of Service) attacks.

About the Author

Jordan Lutke is an intern with 1105 Media.

Featured

  • Ransomware Attacks Rise for the First Time in Six Months

    Ransomware attacks have risen for the first time in six months, increasing by 28% month-on-month to 421 attacks. While overall attack volume remained below 500, the uptick may signal a renewed escalation heading into the year’s most active period for cyber criminals. Read Now

  • Report: 47 Percent of Security Service Providers Are Not Yet Using AI or Automation Tools

    Trackforce, a provider of security workforce management platforms, today announced the launch of its 2025 Physical Security Operations Benchmark Report, an industry-first study that benchmarks both private security service providers and corporate security teams side by side. Based on a survey of over 300 security professionals across the globe, the report provides a comprehensive look at the state of physical security operations. Read Now

    • Guard Services
  • Identity Governance at the Crossroads of Complexity and Scale

    Modern enterprises are grappling with an increasing number of identities, both human and machine, across an ever-growing number of systems. They must also deal with increased operational demands, including faster onboarding, more scalable models, and tighter security enforcement. Navigating these ever-growing challenges with speed and accuracy requires a new approach to identity governance that is built for the future enterprise. Read Now

  • Eagle Eye Networks Launches AI Camera Gun Detection

    Eagle Eye Networks, a provider of cloud video surveillance, recently introduced Eagle Eye Gun Detection, a new layer of protection for schools and businesses that works with existing security cameras and infrastructure. Eagle Eye Networks is the first to build gun detection into its platform. Read Now

  • Report: AI is Supercharging Old-School Cybercriminal Tactics

    AI isn’t just transforming how we work. It’s reshaping how cybercriminals attack, with threat actors exploiting AI to mass produce malicious code loaders, steal browser credentials and accelerate cloud attacks, according to a new report from Elastic. Read Now

New Products

  • 4K Video Decoder

    3xLOGIC’s VH-DECODER-4K is perfect for use in organizations of all sizes in diverse vertical sectors such as retail, leisure and hospitality, education and commercial premises.

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure.

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis.