PowerShell Malware Abuses Registry and DNS TXT Records to Deploy XMRig Crypto Miner
ID: 74aa678a-77b8-54f7-8cb1-b3079cf6afdf
STIX ID: report--74aa678a-77b8-54f7-8cb1-b3079cf6afdf
Feed Name: GBHackers
A K7 Security Labs analysis describes a sophisticated cryptomining campaign that obfuscates multi-stage PowerShell payloads via Registry-resident scripts, DNS TXT records, PNG steganography, and WAV-hosted .NET assemblies to deploy an XMRig RandomX miner; the malware uses in-memory execution, persistence (scheduled tasks and a WMI permanent event), Defender exclusion modifications, and drops WinRing0.sys, and the report includes detailed IOCs (domains, URLs, file hashes, registry path, and a C2 IP).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
