logo

From Scripts to Systems: A Comprehensive Look at Tangerine Turkey Operations

ID: fbdf897e-051b-5b1b-85fc-b499307718ed

STIX ID: report--fbdf897e-051b-5b1b-85fc-b499307718ed

Feed Name: Cybereason Blog

Threat Score
65/100

Date Published: 2025-10-29

Date Updated: 2026-04-27

Author: Cybereason Security Services Team

...
...

Cybereason analyzed the 'Tangerine Turkey' campaign: a USB‑propagating VBScript worm that installs XMRig for unauthorized cryptocurrency mining. The actor abuses legitimate Windows binaries (wscript.exe, printui.exe), uses DLL sideloading, scheduled tasks and a malicious service for persistence, modifies Defender exclusions for defense evasion, and the report includes detailed TTPs, IOCs (file names and SHA256 hashes) and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.