logo

CoinMiner Malware Being Continuously Distributed via USB

ID: 5ac8808f-0979-5887-a4d9-6cc90708eea5

STIX ID: report--5ac8808f-0979-5887-a4d9-6cc90708eea5

Feed Name: ASEC

Threat Score
65/100

Date Published: 2025-11-27

Date Updated: 2026-04-26

Author: ATCP

...
...

**Executive Summary:** AhnLab's analysis describes an active USB-spread coinminer campaign (PrintMiner/DIRTYBULK/CUTFAIL) that tricks users into running a visible "USB Drive.lnk" shortcut which launches VBS/BAT droppers, performs DLL side-loading via printui.exe, registers malicious components with the DcomLaunch service, disables defenses and power-saving, and deploys XMRig for Monero mining; the report includes configuration details and IoCs (hashes, URLs, IPs, domains) useful for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.