logo

PowerShell Malware Abuses Registry and DNS TXT Records to Deploy XMRig Crypto Miner

ID: 74aa678a-77b8-54f7-8cb1-b3079cf6afdf

STIX ID: report--74aa678a-77b8-54f7-8cb1-b3079cf6afdf

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-09-19

Date Updated: 2026-09-19

Author: Divya

...
...

A K7 Security Labs analysis describes a sophisticated cryptomining campaign that obfuscates multi-stage PowerShell payloads via Registry-resident scripts, DNS TXT records, PNG steganography, and WAV-hosted .NET assemblies to deploy an XMRig RandomX miner; the malware uses in-memory execution, persistence (scheduled tasks and a WMI permanent event), Defender exclusion modifications, and drops WinRing0.sys, and the report includes detailed IOCs (domains, URLs, file hashes, registry path, and a C2 IP).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.