XMRig CoinMiner Installed via Game Hacks
ID: 20dbf6f0-7aea-536f-9b1b-f53ce970e5b5
STIX ID: report--20dbf6f0-7aea-536f-9b1b-f53ce970e5b5
Feed Name: ASEC
Threat Score
AhnLab ASEC reports XMRig CoinMiner being distributed through game-hack websites: compressed archives include a downloader (AutoHotkey), tools to disable Windows Defender (dControl.exe), and loader.exe which installs the miner to %ProgramData% and %temp%, edits hosts, disables update/MSRT services, and persists as a service named GoogleUpdateFile; the report includes file hashes and a download URL and warns users against running executables from untrusted game-hack sources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
