logo

AhnLab EDR Detects CoinMiner Propagated via USB in South Korea

ID: 5019784a-f16d-5f9a-93c3-8997895c2df3

STIX ID: report--5019784a-f16d-5f9a-93c3-8997895c2df3

Feed Name: ASEC

Threat Score
60/100

Date Published: 2025-02-06

Date Updated: 2026-04-26

Author: ATCP

...
...

This AhnLab analysis details a CoinMiner campaign that propagates through infected USB drives, hides user files, and executes via generated .vbs/.bat dropper files. The malware creates a misleading "C:\Windows (space)\System32" folder to facilitate privilege escalation, uses DLL side‑loading and PowerShell to add Windows Defender exclusion paths, and maintains persistence through a registered service and scheduled tasks; the report includes EDR detection names and MD5 indicators for detection and investigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.