Hackers are using a layered Windows malware chain to run an XMRig cryptocurrency miner while keeping its key parts out of sight. The operation hides code in the Windows Registry, a PNG image, and files that appear to be ordinary WAV audio, making routine checks less useful. The attack begins with a PowerShell script that retrieves an encoded next stage from a Registry value. It then uses DNS TXT records to find a download location for a PNG file, an approach that extends the kind of registry stored PowerShell payloads previously seen in stealth-focused Windows intrusions. Analysts at K7 Security Labs identified the multi-stage infection after investigating repeated PowerShell alerts on an affected system. K7 Security Labs said in...
Läs hela artikeln hos källan.
Kommentarer (0)
Inga kommentarer ännu. Bli först med att kommentera!