Threat Actors Deploying CoinMiner Malware via USB Drives Infecting Workstations
Cybercriminals are disseminating CoinMiner malware via USB drives, targeting workstations in South Korea to mine Monero cryptocurrency.
Cybercriminals are disseminating CoinMiner malware via USB drives, targeting workstations in South Korea to mine Monero cryptocurrency.
This campaign employs deceptive shortcut files and hidden folders to execute malicious scripts without user awareness.
The attack utilizes VBS, BAT, and DLL files to install XMRig, a cryptocurrency mining tool, on infected systems.
The malware conceals itself in a folder named "sysvolume" on infected USB drives, presenting only a shortcut file labeled "USB Drive.lnk" to the user.
When users click this file, it initiates a series of malicious actions while opening a folder containing the original files.
This tactic allows normal data access, making the infection difficult to detect. ASEC security researchers identified this malware in their analysis of USB-based threats.
Cybercriminals are disseminating CoinMiner malware via USB drives, targeting workstations in South Korea to mine Monero cryptocurrency.
The attackers have refined their techniques since February 2025, with Mandiant categorizing these threats as DIRTYBULK and CUTFAIL in their July 2025 report.
The infection begins when users execute the deceptive shortcut file, running a VBS script with a randomly generated filename like "u566387.vbs".
This script triggers BAT malware, performing operations such as adding Windows Defender exclusion paths and creating a folder with a space in its name at "C:\Windows \System32\" to evade detection.
The BAT script copies and renames the dropper malware as "printui.dll" and loads it through the legitimate "printui.exe" program.
Infection Mechanism and Persistence Tactics
The dropper component ensures persistence by registering a DLL with the DcomLaunch service.
Once registered, the malware, termed PrintMiner, adjusts system power settings to prevent sleep mode and communicates with command-and-control servers to download encrypted payloads.
The decrypted files include XMRig, configured to mine Monero with parameters: -o r2.hashpoolpx[.]net:443 --tls --max-cpu-usage=50 .
The malware monitors running processes and terminates XMRig when users launch games or process monitoring tools like Process Explorer, Task Manager, and System Informer.
This evasion technique helps the miner avoid detection while minimizing performance impacts that could alert users. USB-based attacks remain effective when combined with social engineering.
Based on reporting by Cyber Security News.
