Hackers are using a layered Windows malware chain to run an XMRig cryptocurrency miner while keeping its key parts out of sight. The operation hides code in the Windows Registry, a PNG image, and files that appear to be ordinary WAV audio, making routine checks less useful. The attack begins with a PowerShell script that retrieves an encoded next stage from a Registry value. It then uses DNS TXT records to find a download location for a PNG file, an approach that extends the kind of registry stored PowerShell payloads previously seen in stealth-focused Windows intrusions. Analysts at K7 Security Labs identified the multi-stage infection after investigating repeated PowerShell alerts on an affected system. K7 Security Labs said in...
Læs hele artiklen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!