logo

Fake MSI Afterburner Sites Delivering Coin-Miner

ID: fe6df00b-eaea-5ffe-ba4d-05f6b9901846

STIX ID: report--fe6df00b-eaea-5ffe-ba4d-05f6b9901846

Feed Name: Cyble Blog

Threat Score
70/100

Date Published: 2025-05-21

Date Updated: 2026-07-20

...
...

Cyble Research & Intelligence Labs describes an active phishing campaign that impersonates MSI Afterburner to trick users into installing a bundled installer which drops a PyInstaller-based loader (browser_assistant.exe) that decodes shellcode, retrieves an encoded XMR miner from GitHub, injects it into explorer.exe for stealthy cryptocurrency mining, and exfiltrates system details to a listed C2; the report includes technical analysis, process and injection details, command-line mining arguments, IOCs (hashes, domains, IPs, URLs), and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.