Threat actors have continued leveraging USB drives to spread the CoinMiner cryptocurrency mining malware as part of an ongoing attack campaign aimed at South Korean workstations, Cyber Security News reports.
Malicious shortcut files have been used to facilitate the execution of a VBS script, which then prompts BAT malware to include Windows Defender exclusion paths and establish a new folder within the System32 folder before renaming the dropper malware, according to an analysis from the AhnLab Security Intelligence Center. After DLL registration with the DcomLaunch service for persistence, the PrintMiner malware proceeds to manipulate system power settings and retrieve encrypted payloads, one of which is XMRig for Monero mining.
Opening games or process monitoring tools was found to have terminated XMRig to curb detection. Such findings show the growing refinement in USB-based threats, which researchers noted to be highly effective when used alongside social engineering tactics.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
