Dual Malware Infection Targets Cryptocurrency Users: What You Need To Know
ID: c6b3e316-0bf4-5303-aed7-397fbdab6c1b
STIX ID: report--c6b3e316-0bf4-5303-aed7-397fbdab6c1b
Feed Name: Cyble Blog
This report details a dual-malware campaign in which a .NET Coinminer (sample SHA256 ca43548571c559a85f937635951c1ebd2a26d2ad84a8cc96f669d6b48fd2b9b7) persists via scheduled tasks and Defender exclusions to mine cryptocurrency through the Luckpool mining pool, while additionally downloading and executing a clipper that monitors clipboard contents and replaces cryptocurrency addresses with attacker-controlled wallets to steal funds; the report provides IOCs (file hashes, distribution URL, wallet addresses), behavior analysis, MITRE ATT&CK mappings, and defensive recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
