From Scripts to Systems: A Comprehensive Look at Tangerine Turkey Operations
ID: fbdf897e-051b-5b1b-85fc-b499307718ed
STIX ID: report--fbdf897e-051b-5b1b-85fc-b499307718ed
Feed Name: Cybereason Blog
Threat Score
Cybereason analyzed the 'Tangerine Turkey' campaign: a USB‑propagating VBScript worm that installs XMRig for unauthorized cryptocurrency mining. The actor abuses legitimate Windows binaries (wscript.exe, printui.exe), uses DLL sideloading, scheduled tasks and a malicious service for persistence, modifies Defender exclusions for defense evasion, and the report includes detailed TTPs, IOCs (file names and SHA256 hashes) and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
