Threat Advisory: XMRig Cryptomining By Way Of TeamViewer
ID: 19706c16-a0e6-5ef3-b6c1-51d00603e6b8
STIX ID: report--19706c16-a0e6-5ef3-b6c1-51d00603e6b8
Feed Name: Huntress Blog
Huntress SOC investigated a series of XMRig cryptocurrency miner infections discovered in May 2023 where attackers gained initial access via compromised TeamViewer credentials, used clipboard and PowerShell/batch scripts to download and execute a miner payload from domains hosted on OSS-accelerate and other locations, and persisted via a Windows service; the report includes timelines reconstructed from EDR and Windows event logs, IOCs (malicious domains and wallet), MITRE ATT&CK mappings, and a high-fidelity EQL detection to identify similar infections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
