Hackers Hide PowerShell Malware in Registry, PNG and WAV Files to Deploy XMRig Miner
ID: 9532b137-5300-5f76-b5fc-9663b5889d3a
STIX ID: report--9532b137-5300-5f76-b5fc-9663b5889d3a
Feed Name: Cyber Press
Researchers uncovered a sophisticated Windows cryptomining campaign that uses Registry-resident PowerShell loaders, DNS TXT records, and steganographic payloads embedded in PNG and WAV files to reconstruct and execute .NET assemblies in memory; the final payload is an XMRig RandomX miner with persistence mechanisms (scheduled tasks, WMI subscription), Defender exclusions, and a kernel driver for CPU optimization. The report includes detailed TTP descriptions, C2 behaviours, and a list of IOCs (domains, URLs, file hashes, registry keys, and an IP:port) for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
