logo

Threat Actors Deploying CoinMiner Malware via USB Drives Infecting Workstations

ID: 755d9bb1-8311-5fde-902c-9185104a9105

STIX ID: report--755d9bb1-8311-5fde-902c-9185104a9105

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-12-05

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A USB-spread CoinMiner campaign in South Korea uses deceptive shortcut files and a hidden “sysvolume” folder to execute VBS/BAT/DLL dropper components that install XMRig for Monero mining; the malware establishes persistence by registering a DLL with the DcomLaunch service, modifies Defender exclusions, downloads encrypted payloads from C2 servers, and employs process-monitoring evasion to avoid detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.