USB-based CoinMiner Malware Targets South Korean Workstations

USB-based CoinMiner Malware Targets South Korean Workstations

First seen 9 Dec 2025, 01:47 UTC SocprimeScworld 86% similarity 37.6

Article Content

Browse articles
ThreatCluster

CoinMiner malware is being spread through USB drives in South Korea, utilizing malicious shortcut files to execute VBS scripts that deploy BAT malware. This attack campaign aims to compromise workstations by establishing Windows Defender exclusion paths and delivering cryptocurrency miners like PrintMiner and XMRig.

ThreatCluster AI How this analysis works

Community

Browse all →

Tracked Entities in This Story