DirtyMoe Malware Infects 2,000+ Ukrainian Computers for DDoS and Cryptojacking
ID: 957e2c08-650f-5af2-9cae-fbe91e050508
STIX ID: report--957e2c08-650f-5af2-9cae-fbe91e050508
Feed Name: The Hacker News
Threat Score
CERT-UA reports that over 2,000 Ukrainian computers have been infected by the DirtyMoe malware—used for cryptojacking and DDoS—and that infections leverage delivery mechanisms like Purple Fox and malicious installers; separately, a phishing campaign (STEADY#URSA) is distributing a PowerShell backdoor called SUBTLE-PAWS linked to Gamaredon/Shuckworm, which uses Telegraph for C2, registry-stored PowerShell for persistence, and can propagate via removable drives.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
