Scworld
USB-based CoinMiner Malware Targets South Korean Workstations
First seen 9 Dec 2025, 01:47 UTC
•
•86% similarity
•37.6
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
CoinMiner malware is being spread through USB drives in South Korea, utilizing malicious shortcut files to execute VBS scripts that deploy BAT malware. This attack campaign aims to compromise workstations by establishing Windows Defender exclusion paths and delivering cryptocurrency miners like PrintMiner and XMRig.
ThreatCluster AI
How this analysis works