logo

DirtyMoe Malware Infects 2,000+ Ukrainian Computers for DDoS and Cryptojacking

ID: 957e2c08-650f-5af2-9cae-fbe91e050508

STIX ID: report--957e2c08-650f-5af2-9cae-fbe91e050508

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2024-02-02

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

CERT-UA reports that over 2,000 Ukrainian computers have been infected by the DirtyMoe malware—used for cryptojacking and DDoS—and that infections leverage delivery mechanisms like Purple Fox and malicious installers; separately, a phishing campaign (STEADY#URSA) is distributing a PowerShell backdoor called SUBTLE-PAWS linked to Gamaredon/Shuckworm, which uses Telegraph for C2, registry-stored PowerShell for persistence, and can propagate via removable drives.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.