Skip to main content

From Registry-Stored PowerShell to In-Memory Cryptocurrency Mining: A Multi-Stage Infection Chain

0
Medium
Published: 09/21/2026 (09/21/2026, 15:16:13 UTC)
Source: AlienVault OTX General

Description

This is a sophisticated multi-stage infection campaign that uses PowerShell scripts stored in the Windows Registry, DNS TXT record exploitation, and steganographically encoded data within image and WAV audio files to deploy cryptocurrency mining malware. The attackers employ multiple evasion techniques including security control tampering and in-memory execution to avoid detection. Payloads are reconstructed from distributed sources rather than being written directly to disk, enabling covert and persistent cryptocurrency mining operations on compromised systems.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/21/2026, 15:47:24 UTC

Technical Analysis

The threat involves a complex infection chain leveraging Registry-based PowerShell payload storage, DNS TXT records, and data hidden in media files using steganography. The attackers use obfuscation and evasion techniques such as in-memory execution and security control tampering to maintain stealth. The final goal is to covertly deploy cryptocurrency mining malware while ensuring persistence through multiple redundant mechanisms. This campaign does not rely on direct disk payloads but reconstructs malicious code from dispersed sources, complicating detection and remediation.

Potential Impact

Compromised systems are covertly used for cryptocurrency mining, which can degrade system performance and increase operational costs. The multi-layered evasion and persistence techniques make detection and removal challenging, potentially allowing long-term unauthorized access and resource abuse.

Defensive Guidance

No official patch or fix is applicable as this is a multi-stage infection campaign rather than a software vulnerability. Mitigation should focus on detecting and blocking the use of Registry-based PowerShell payloads, monitoring for suspicious DNS TXT record queries, and identifying steganographic data in media files. Security controls should be hardened to prevent tampering, and in-memory execution monitoring should be enabled. Incident response should include thorough system inspection for persistence mechanisms and removal of all malicious components.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://labs.k7computing.com/index.php/from-registry-stored-powershell-to-in-memory-cryptocurrency-mining-a-multi-stage-infection-chain/"]
Pulse Id
6ab14a3d40e63bae6b1e58b3

Indicators of Compromise

Hash

ValueDescriptionCopy
hash94b50ace73cc03790678c73b867be129
hashbe860a15b7e5d44b0b3d67f598238fad
hashc024189e1e7fa0ae6d24353367e8b98d
hashed276b2312f641b00f87fa18e85c48eb
hashf1d2fdb7f3b699da69a050c5352a33c2
hashf94de28bd66afc4679f546500db184d4
hash608c34e10713278fbe80b7cb5dedb0555cff1559
hashd2a98fe01257d897a0dc5994392cbde9089fadf9
hash39368a9465aca3286e4436650b7a33b39a9294a81f3e681e056c9da0550e27c4
hash9839448acc050331b5713882a25b863b47993a0f2859b4820563e34c72f5b679

Threat ID: 6ab14dea55bf5e2cf5168606

Added to database: 09/21/2026, 15:31:54 UTC

Last enriched: 09/21/2026, 15:47:24 UTC

Last updated: 09/21/2026, 18:45:41 UTC

Views: 9

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses