CoinMiner malware continues to propagate through USB drives in South Korea, leveraging a hidden shortcut that triggers VBS and BAT scripts, which in turn stage multiple components that ultimately deliver a cryptocurrency-mining payload.
The report outlines the directory structure on the infected USB, the execution chain from the shortcut through multiple dropper stages, registration under the DcomLaunch service, and deployment of PrintMiner and XMRig cryptocurrency miners.
Users should keep OS and software patched, block execution of untrusted shortcut files, use up-to-date antivirus tools, and deny access to known malicious infrastructure.
Detect the malicious shortcut and its related scripts, monitor for creation of dropper files and DCOM registrations, and block network traffic to the identified mining command-and-control domains and IP address.
Prerequisite: The Telemetry & Baseline Pre‑flight Check must have passed.
Rationale: This section details the precise execution of the adversary technique (TTP) designed to trigger the detection rule. The commands and narrative MUST directly reflect the TTPs identified and aim to generate the exact telemetry expected by the detection logic. Abstract or unrelated examples will lead to misdiagnosis.
Attack Narrative & Commands:
Regression Test Script: The script below automates the three stages, ensuring reproducibility.
Cleanup Commands: (If the above script fails or you prefer manual cleanup)
Join SOC Prime's Detection as Code platform to improve visibility into threats most relevant to your business. To help you get started and drive immediate value, book a meeting now with SOC Prime experts.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
