Invisible miners: unveiling GHOSTENGINE’s crypto mining operations
ID: d1c5a398-7432-5957-9ffb-2ac7a9973217
STIX ID: report--d1c5a398-7432-5957-9ffb-2ac7a9973217
Feed Name: Elastic Security Labs
Threat Score
Elastic Security Labs documents the REF4578 intrusion set (primary payload GHOSTENGINE), detailing a complex cryptomining campaign that uses vulnerable third-party drivers to terminate and delete endpoint security agents, deploys persistent scheduled tasks and a service DLL backdoor, and installs XMRig for Monero mining; the report includes module analyses, IoCs (file hashes, domains, IPs), and miner payment identifiers for tracking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
