logo

CoinMiner Malware Distributed via USB

ID: c0dbfc03-891f-52d9-9d39-9baee5057a5f

STIX ID: report--c0dbfc03-891f-52d9-9d39-9baee5057a5f

Feed Name: ASEC

Threat Score
70/100

Date Published: 2025-02-05

Date Updated: 2026-04-26

Author: ATCP

...
...

**Executive Summary:** AhnLab ASEC reports a USB-propagated Monero-mining campaign in South Korea that automates infection via shortcut execution, registers persistence as a service, alters system settings (adds Windows Defender exceptions, disables HVCI, changes power/hibernation), uses DLL sideloading and PostgreSQL-based C2 to deploy coinminer, and has generated measurable profits; the report includes MD5 hashes, distribution URLs, and C2/database details and recommends keeping security software up-to-date.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.