Novel EDR-Killing 'GhostEngine' Malware Is Built for Stealth
ID: 24bd4141-337c-509f-b673-57d50cfc89d3
STIX ID: report--24bd4141-337c-509f-b673-57d50cfc89d3
Feed Name: Dark Reading
Date Published: 2024-05-22
Date Updated: 2026-05-05
Author: Elizabeth Montalbano, Contributing Writer
GhostEngine, attributed to an intrusion set labeled REF4578, is a modular C++ malware used in a cryptomining campaign that leverages vulnerable drivers to terminate and delete EDR agents, establish persistence, deploy a backdoor, and install the XMRig Monero miner. Researchers (Elastic Security Labs and Antiy Labs) observed initial execution via a trojanized TiWorker.exe that launches PowerShell orchestration, downloads modules and configurations from C2, and performs log clearing, Defender tampering, and other evasive actions; detection guidance focuses on suspicious PowerShell, unusual execution paths, driver loading, and mining-related network traffic.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
