logo

GHOSTENGINE Exploits Vulnerable Drivers to Disable EDRs in Cryptojacking Attack

ID: cf9f42bd-ac21-5d6b-bcb4-e0bd8a47e757

STIX ID: report--cf9f42bd-ac21-5d6b-bcb4-e0bd8a47e757

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-05-22

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Elastic Security Labs and other researchers have identified a sophisticated cryptojacking campaign (REF4578 / GHOSTENGINE, also seen as HIDDEN SHOVEL) that uses BYOVD (Bring Your Own Vulnerable Driver) attacks to load vulnerable signed drivers (e.g., aswArPot.sys, iobitunlockers.sys), terminate and delete EDR/security agents, and deploy the XMRig miner. The infection chain begins with Tiworker.exe executing obfuscated PowerShell (masquerading as PNGs like get.png, backup.png, kill.png) to fetch modules and payloads, establishes persistence via scheduled tasks and a DLL, cleans event logs, uses HTTP/FTP fallback C2s, and demonstrates resilience and sophistication; the report also links this activity to broader exploitation trends (Log4j-based miner distribution) and novel evasion techniques (EDRaser, HookChain).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.