Kryptovaluta-ticker:
sysadmin fra Cyber Security News

Hackers Hide XMRig Miner in Windows Registry, PNG and WAV Files to Evade Detection

Tushar Subhra Dutta
4 hours ago
7 Visninger
0 Kommentarer
Hackers Hide XMRig Miner in Windows Registry, PNG and WAV Files to Evade Detection

Hackers are using a layered Windows malware chain to run an XMRig cryptocurrency miner while keeping its key parts out of sight. The operation hides code in the Windows Registry, a PNG image, and files that appear to be ordinary WAV audio, making routine checks less useful. The attack begins with a PowerShell script that retrieves an encoded next stage from a Registry value. It then uses DNS TXT records to find a download location for a PNG file, an approach that extends the kind of registry stored PowerShell payloads previously seen in stealth-focused Windows intrusions. Analysts at K7 Security Labs identified the multi-stage infection after investigating repeated PowerShell alerts on an affected system. K7 Security Labs said in...

Læs hele artiklen hos kilden.

Deltag i diskussionen — kommenter, stem og del links.

Registrer
Var dette nyttigt?
Del:

Kommentarer (0)

Log venligst ind eller opret dig for at deltage i diskussionen

Ingen kommentarer ennå. Bli den første til å kommentere!