Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Threat Actors Distribute CoinMiner Malware through USB Drives to Infect Workstations

Cybercriminals have been leveraging USB drives as vectors for distributing CoinMiner malware, which establishes persistent cryptocurrency-mining operations on compromised systems. This threat employs social engineering and evasion techniques to mine…

Cybercriminals have been leveraging USB drives as vectors for distributing CoinMiner malware, which establishes persistent cryptocurrency-mining operations on compromised systems. This threat employs social engineering and evasion techniques to mine Monero cryptocurrency while avoiding detection.

In February 2025, the AhnLab Security Intelligence Center (ASEC) confirmed in their report "Cases of CoinMiner Being Spread via USB" that this malware is prevalent in South Korea. In July 2025, Mandiant released a report categorizing the malware as DIRTYBULK and CUTFAIL.

The attack method involves a deceptive file structure on the infected USB drive, displaying a "USB Drive.lnk" shortcut and hidden folders. Upon execution, it triggers VBS malware, which initiates a BAT script performing critical functions to mask the infection and maintain persistence.

This threat employs social engineering and evasion techniques to mine Monero cryptocurrency while avoiding detection.
William Hayes · Thehackingpost

The malware employs DLL side-loading techniques to execute malicious operations. It uses multiple dropper stages to deploy the final payload, creating and executing various files to ensure persistence. The final stage involves the PrintMiner, which modifies system settings to maintain continuous mining operations and communicates with a command and control server.

The threat actors implemented evasion mechanisms to avoid detection. The XMRig miner monitors processes, activating only when specific applications are not running. It checks for process inspection tools to conceal mining activity and monitors game client processes to avoid alerting users during gaming sessions. The miner limits CPU usage and uses TLS connections to reduce network traffic patterns.

Advertisement

This campaign highlights the continued viability of USB-based malware distribution. Organizations should implement USB device controls, educate users about security risks, and deploy detection solutions to identify suspicious activities. Regular monitoring for unauthorized cryptocurrency mining processes can aid in detecting infections.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories