logo

Distribution of Zephyr CoinMiner Using Autoit

ID: 755db9b6-c2b3-5174-b7e3-7543ab656c4f

STIX ID: report--755db9b6-c2b3-5174-b7e3-7543ab656c4f

Feed Name: ASEC

Threat Score
50/100

Date Published: 2024-02-02

Date Updated: 2026-04-26

Author: ov5925

...
...

**Executive Summary:** AhnLab ASEC identified a multi-stage CoinMiner campaign that distributes a Zephyr miner inside a compressed NSIS installer named WINDOWS_PY_M3U_EXPLOIT_2024.7z; the package drops and executes Javascript which decodes a Base64 AutoIt executable that extracts 32/64-bit miner binaries and installs Helper.exe to %USER%/AppData/Roaming. The report documents the miner's pool (zeph.kryptex.network:8888), hardcoded wallet, the malware execution flow, detection names (V3 aliases), and MD5 IOCs to support detection and remediation efforts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.