Threat actors have continued leveraging USB drives to spread the CoinMiner cryptocurrency mining malware as part of an ongoing attack campaign aimed at South Korean workstations, Cyber Security News reports.Malicious shortcut files have been used to facilitate the execution of a VBS script, which then prompts BAT malware to include Windows Defender exclusion paths and establish a new folder within the System32 folder before renaming the dropper malware, according to an analysis from the AhnLab Security Intelligence Center. After DLL registration with the DcomLaunch service for persistence, the PrintMiner malware proceeds to manipulate system power settings and retrieve encrypted payloads, one of which is XMRig for Monero mining.Opening games or process monitoring tools was found to have terminated XMRig to curb detection. Such findings show the growing refinement in USB-based threats, which researchers noted to be highly effective when used alongside social engineering tactics.
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds




