CoinMiner Malware Distributed via USB
ID: c0dbfc03-891f-52d9-9d39-9baee5057a5f
STIX ID: report--c0dbfc03-891f-52d9-9d39-9baee5057a5f
Feed Name: ASEC
**Executive Summary:** AhnLab ASEC reports a USB-propagated Monero-mining campaign in South Korea that automates infection via shortcut execution, registers persistence as a service, alters system settings (adds Windows Defender exceptions, disables HVCI, changes power/hibernation), uses DLL sideloading and PostgreSQL-based C2 to deploy coinminer, and has generated measurable profits; the report includes MD5 hashes, distribution URLs, and C2/database details and recommends keeping security software up-to-date.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
