HomeCyber BalkansPowerShell Malware Exploits Registry and DNS TXT Records for XMRig Crypto Miner...

PowerShell Malware Exploits Registry and DNS TXT Records for XMRig Crypto Miner Deployment

Published on

spot_img

A sophisticated cryptomining campaign has recently come to light, employing intricate layers of obfuscation to mask its malicious intentions. This operation is designed to deploy a cryptocurrency miner based on XMRig, utilizing a series of techniques that involve various mediums including malicious PowerShell scripts, Windows Registry entries, DNS TXT records, and even seemingly innocuous file formats such as PNG images and WAV audio files.

Security measures were alerted when persistent suspicious PowerShell activities were detected within systems. The infection was initiated through a PowerShell command that bypassed standard execution policies using the -NoProfile option, retrieving malicious scripts stored in the Windows Registry at the location HKLM:\Software\uf42a9660377\vstdfehzr.

### PowerShell Malware Exploiting Registry

The attackers have cleverly avoided conventional methods of saving malicious scripts by encoding PowerShell instructions directly within the Windows Registry. This loader retrieves, decodes, and executes the PowerShell data in memory, which significantly reduces its visibility on disk and, consequently, complicates detection efforts.

According to K7 Security Labs, the encoded script in the Registry was engineered to query DNS TXT records linked to sslvalidcert[.]com, which later transitioned to txtcdn[.]net. The response from these queries contained decimal values in a comma-separated format that the malware decoded into ASCII text. This method reconstructed a URL leading to a PNG image hosted at frames-1zm[.]pages[.]dev.

Rather than being a conventional image file, this PNG was repurposed as a covert payload container. The PowerShell script subsequently extracted data concealed within the red pixel channel of the image, reconstructing the hidden code and executing it on the victim’s machine. This step was crucial for establishing communication with the command-and-control (C2) servers and retrieving further instructions.

The operation escalated as the malware deleted files from the Public\Music directory, subsequently downloading a ZIP archive filled with audio track disguises labeled as files such as Atsg.wav and Tmav.wav. Despite their visual facade, these files harbored encoded malicious PowerShell scripts and .NET payloads embedded within them.

### Stages of Persistence and Evasion

The first stage using Atsg.wav aimed at ensuring persistence while evading detection. This involved modifying PowerShell settings, diminishing security protocols and telemetry, and adding broad exclusions to Microsoft Defender. Furthermore, the malware cleared PowerShell command history logs and created hidden Scheduled Tasks designed to execute commands upon user logon and at regular intervals.

Moreover, the malware established a permanent event subscription through Windows Management Instrumentation (WMI) that scrutinized Registry events, triggering execution under specific conditions. This innovative approach not only enhanced the malware’s persistence but also provided means to maintain access even after system reboots.

A hardware identifier, unique to each infected system, was generated and stored in the Registry. To facilitate communication with the C2 servers, the malware executed DNS-over-HTTPS queries to discover TXT records relevant to httptls[.]org.

As the attack chain progressed, the malware communicated with the identified C2 infrastructure using HTTP or HTTPS POST requests, employing an X-HWID header to identify the targeted systems.

Notably, the WAV file stages skipped the regular 44-byte WAV header, reconstructing hidden .NET assemblies by merging lower nibbles from adjacent bytes. This avoided the need to write executable files on disk, further challenging detection efforts.

### Deployment of XMRig Miner

The culmination of this elaborate scheme was the deployment of an XMRig mining solution, configured to utilize the RandomX rx/0 algorithm. The malware fetched additional configuration data remotely, which included critical parameters such as mining pool details, wallet addresses, and CPU usage specifics. It also deployed a driver known as WinRing0.sys, widely used for optimizing CPU performance during RandomX mining activities.

### Indicators of Compromise

For those monitoring for potential compromises, specific indicators have emerged from this complex operation, including registry paths that store the encoded PowerShell stage and domains used for DNS TXT payload delivery.

The domains sslvalidcert[.]com and txtcdn[.]net played pivotal roles in the operation, as did various URLs that served as repositories for the PNG payload container, as well as maliciously disguised WAV files. For organizations seeking to bolster their defenses, recognizing these signs, along with the corresponding MD5 hashes of suspicious files, is vital in mitigating the risks posed by such cryptomining operations.

In conclusion, the obfuscation employed in this cryptomining campaign exemplifies the evolving sophistication of cyber threats, necessitating robust security measures and vigilance to detect and counteract such attempts in the digital landscape.

Source link

Latest articles

SE Labs Introduces PIVOT Testing Program for Cybersecurity Vendors

SE Labs Launches New Cybersecurity Testing Program: PIVOT On September 15, SE Labs, a prominent...

US, UK, and Dutch Reveal Iranian Chosen Brick Malware

Cybersecurity agencies from the United States, the United Kingdom, and the Netherlands have come...

AI-Powered RatHat Android Trojan Targets Bank Credentials, PINs, and MFA Codes

A New Threat Emerges: The AI-Powered RatHat Android Trojan In a significant advancement in the...

CSIDES Reveals Complete Agenda for 2026 Cybersecurity Community Event

CSIDES Unveils Engaging Agenda for 2026 Cybersecurity Community Event in Weston-super-Mare CSIDES has announced its...

More like this

SE Labs Introduces PIVOT Testing Program for Cybersecurity Vendors

SE Labs Launches New Cybersecurity Testing Program: PIVOT On September 15, SE Labs, a prominent...

US, UK, and Dutch Reveal Iranian Chosen Brick Malware

Cybersecurity agencies from the United States, the United Kingdom, and the Netherlands have come...

AI-Powered RatHat Android Trojan Targets Bank Credentials, PINs, and MFA Codes

A New Threat Emerges: The AI-Powered RatHat Android Trojan In a significant advancement in the...