AhnLab EDR Detects CoinMiner Propagated via USB in South Korea
ID: 5019784a-f16d-5f9a-93c3-8997895c2df3
STIX ID: report--5019784a-f16d-5f9a-93c3-8997895c2df3
Feed Name: ASEC
This AhnLab analysis details a CoinMiner campaign that propagates through infected USB drives, hides user files, and executes via generated .vbs/.bat dropper files. The malware creates a misleading "C:\Windows (space)\System32" folder to facilitate privilege escalation, uses DLL side‑loading and PowerShell to add Windows Defender exclusion paths, and maintains persistence through a registered service and scheduled tasks; the report includes EDR detection names and MD5 indicators for detection and investigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
