Multicomponent Malware Targeting Cryptocurrency
ID: f575f922-ac9d-51d1-9bc3-24bbc0c0e4cc
STIX ID: report--f575f922-ac9d-51d1-9bc3-24bbc0c0e4cc
Feed Name: Zscaler Security Research Blog
Threat Score
**Executive summary:** Zscaler ThreatLabZ identified a downloader that persists under AppData, fetches and deploys a password stealer and a Monero/Aeon coinminer (injecting into explorer.exe), exfiltrates browser credentials via email attachments, and mines cryptocurrency using listed pool endpoints and infrastructure; notable IoCs include https://leletorrents.info/22112995, https://crackpoint.xyz/22112995, and IP 159.89.88.49:14254.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
