logo

Tangerine Turkey mines cryptocurrency in global campaign

ID: 200e9f4e-0bc8-57f2-8a85-8562f3ace101

STIX ID: report--200e9f4e-0bc8-57f2-8a85-8562f3ace101

Feed Name: Red Canary

Threat Score
70/100

Date Published: 2025-01-23

Date Updated: 2026-04-29

Author: Stef Rand

...
...

Tangerine Turkey is a USB-spread VBScript worm that uses a printui DLL hijack and DLL side-loading to install cryptomining software (including XMRig) and pull configuration from attacker-controlled PostgreSQL databases, websites, and GitHub repositories; Red Canary links it to the larger "Universal Mining" operation (reported to have infected ~270,741 systems across 135 countries) and provides detection advice focusing on suspicious relocations of printui.exe and associated IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.