Hidden cryptocurrency mining and theft campaign affected over 28,000 users
ID: 691083fa-4ece-586a-b1d7-c8e5c612f4fd
STIX ID: report--691083fa-4ece-586a-b1d7-c8e5c612f4fd
Feed Name: Dr.Web News
Threat Score
**Executive summary:** Doctor Web identified a large-scale malware campaign distributing AutoIt-based trojans disguised as legitimate installers and system components, which deploy a stealthy cryptominer and a clipboard-clipper via encrypted self-extracting archives (hosted on GitHub/YouTube links); the malware uses IFEO persistence, process hollowing, legitimate signed DLLs with embedded scripts, and Ncat for network access, and has affected over 28,000 victims (primarily in Russia).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
