CoinMiner Malware Being Continuously Distributed via USB
ID: 5ac8808f-0979-5887-a4d9-6cc90708eea5
STIX ID: report--5ac8808f-0979-5887-a4d9-6cc90708eea5
Feed Name: ASEC
**Executive Summary:** AhnLab's analysis describes an active USB-spread coinminer campaign (PrintMiner/DIRTYBULK/CUTFAIL) that tricks users into running a visible "USB Drive.lnk" shortcut which launches VBS/BAT droppers, performs DLL side-loading via printui.exe, registers malicious components with the DcomLaunch service, disables defenses and power-saving, and deploys XMRig for Monero mining; the report includes configuration details and IoCs (hashes, URLs, IPs, domains) useful for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
