logo

GhostEngine mining attacks kill EDR security using vulnerable drivers

ID: 273626c5-0e9d-55a6-aa23-7f2cbce34825

STIX ID: report--273626c5-0e9d-55a6-aa23-7f2cbce34825

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2024-05-21

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A crypto-mining campaign named REF4578 uses a staged loader (Tiworker.exe downloading a PowerShell script get.png) to install GhostEngine, which disables endpoint security by loading vulnerable kernel drivers (aswArPots.sys, IObitUnlockers.sys), creates persistence via scheduled tasks and a service-loaded DLL (oci.dll), and deploys XMRig for covert mining; Elastic Security and Antiy published detection guidance and YARA rules but the actor and target scope remain unattributed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.