Anti-Coinminer Mining Campaign
ID: 8bbca158-ad65-505f-86a9-e3c1eb750cf4
STIX ID: report--8bbca158-ad65-505f-86a9-e3c1eb750cf4
Feed Name: Zscaler Security Research Blog
Zscaler ThreatLabZ analyzes an 'AntiCoinMiner' cryptomining campaign that uses fake coin-blocker websites to distribute two malware variants which deploy Monero miners (xmrig and xmr-stak). The report details infection chains (batch/PowerShell scripts, SFX archives), persistence via services and PaExec-based privilege escalation, process injection to hide miner execution, and a backdoor in an off-the-shelf miner that siphons mining time to the original author; it includes MD5 hashes, malicious URLs, and wallet addresses as IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
