Fake MSI Afterburner Sites Delivering Coin-Miner
ID: fe6df00b-eaea-5ffe-ba4d-05f6b9901846
STIX ID: report--fe6df00b-eaea-5ffe-ba4d-05f6b9901846
Feed Name: Cyble Blog
Cyble Research & Intelligence Labs describes an active phishing campaign that impersonates MSI Afterburner to trick users into installing a bundled installer which drops a PyInstaller-based loader (browser_assistant.exe) that decodes shellcode, retrieves an encoded XMR miner from GitHub, injects it into explorer.exe for stealthy cryptocurrency mining, and exfiltrates system details to a listed C2; the report includes technical analysis, process and injection details, command-line mining arguments, IOCs (hashes, domains, IPs, URLs), and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
