ReasonLabs reported that the miner’s file name translates from the original Russian, “spiderman_net_putidomoi.torrent.exe,” to “spiderman_no_wayhome.torrent.exe” in English and is capable of adding exclusions to Windows Defender.
It also adds a “watchdog process” for persistence.
Once the cryptominer is downloaded, the victim might not immediately be aware it’s there, running in the background, draining both power and CPU capacity.
If downloading potentially dodgy content is a must, the ReasonLabs analysts recommended that users double-check the file extension to any movie file to make sure it ends with .mp4, rather than .exe.