From Registry-Stored PowerShell to In-Memory Cryptocurrency Mining: A Multi-Stage Infection Chain
This is a sophisticated multi-stage infection campaign that uses PowerShell scripts stored in the Windows Registry, DNS TXT record exploitation, and steganographically encoded data within image and WAV audio files to deploy cryptocurrency mining malware. The attackers employ multiple evasion techniques including security control tampering and in-memory execution to avoid detection. Payloads are reconstructed from distributed sources rather than being written directly to disk, enabling covert and persistent cryptocurrency mining operations on compromised systems.
AI Analysis
Technical Summary
The threat involves a complex infection chain leveraging Registry-based PowerShell payload storage, DNS TXT records, and data hidden in media files using steganography. The attackers use obfuscation and evasion techniques such as in-memory execution and security control tampering to maintain stealth. The final goal is to covertly deploy cryptocurrency mining malware while ensuring persistence through multiple redundant mechanisms. This campaign does not rely on direct disk payloads but reconstructs malicious code from dispersed sources, complicating detection and remediation.
Potential Impact
Compromised systems are covertly used for cryptocurrency mining, which can degrade system performance and increase operational costs. The multi-layered evasion and persistence techniques make detection and removal challenging, potentially allowing long-term unauthorized access and resource abuse.
Mitigation Recommendations
No official patch or fix is applicable as this is a multi-stage infection campaign rather than a software vulnerability. Mitigation should focus on detecting and blocking the use of Registry-based PowerShell payloads, monitoring for suspicious DNS TXT record queries, and identifying steganographic data in media files. Security controls should be hardened to prevent tampering, and in-memory execution monitoring should be enabled. Incident response should include thorough system inspection for persistence mechanisms and removal of all malicious components.
Indicators of Compromise
- hash: 94b50ace73cc03790678c73b867be129
- hash: be860a15b7e5d44b0b3d67f598238fad
- hash: c024189e1e7fa0ae6d24353367e8b98d
- hash: ed276b2312f641b00f87fa18e85c48eb
- hash: f1d2fdb7f3b699da69a050c5352a33c2
- hash: f94de28bd66afc4679f546500db184d4
- hash: 608c34e10713278fbe80b7cb5dedb0555cff1559
- hash: d2a98fe01257d897a0dc5994392cbde9089fadf9
- hash: 39368a9465aca3286e4436650b7a33b39a9294a81f3e681e056c9da0550e27c4
- hash: 9839448acc050331b5713882a25b863b47993a0f2859b4820563e34c72f5b679
From Registry-Stored PowerShell to In-Memory Cryptocurrency Mining: A Multi-Stage Infection Chain
Description
This is a sophisticated multi-stage infection campaign that uses PowerShell scripts stored in the Windows Registry, DNS TXT record exploitation, and steganographically encoded data within image and WAV audio files to deploy cryptocurrency mining malware. The attackers employ multiple evasion techniques including security control tampering and in-memory execution to avoid detection. Payloads are reconstructed from distributed sources rather than being written directly to disk, enabling covert and persistent cryptocurrency mining operations on compromised systems.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The threat involves a complex infection chain leveraging Registry-based PowerShell payload storage, DNS TXT records, and data hidden in media files using steganography. The attackers use obfuscation and evasion techniques such as in-memory execution and security control tampering to maintain stealth. The final goal is to covertly deploy cryptocurrency mining malware while ensuring persistence through multiple redundant mechanisms. This campaign does not rely on direct disk payloads but reconstructs malicious code from dispersed sources, complicating detection and remediation.
Potential Impact
Compromised systems are covertly used for cryptocurrency mining, which can degrade system performance and increase operational costs. The multi-layered evasion and persistence techniques make detection and removal challenging, potentially allowing long-term unauthorized access and resource abuse.
Defensive Guidance
No official patch or fix is applicable as this is a multi-stage infection campaign rather than a software vulnerability. Mitigation should focus on detecting and blocking the use of Registry-based PowerShell payloads, monitoring for suspicious DNS TXT record queries, and identifying steganographic data in media files. Security controls should be hardened to prevent tampering, and in-memory execution monitoring should be enabled. Incident response should include thorough system inspection for persistence mechanisms and removal of all malicious components.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://labs.k7computing.com/index.php/from-registry-stored-powershell-to-in-memory-cryptocurrency-mining-a-multi-stage-infection-chain/"]
- Pulse Id
- 6ab14a3d40e63bae6b1e58b3
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash94b50ace73cc03790678c73b867be129 | — | |
hashbe860a15b7e5d44b0b3d67f598238fad | — | |
hashc024189e1e7fa0ae6d24353367e8b98d | — | |
hashed276b2312f641b00f87fa18e85c48eb | — | |
hashf1d2fdb7f3b699da69a050c5352a33c2 | — | |
hashf94de28bd66afc4679f546500db184d4 | — | |
hash608c34e10713278fbe80b7cb5dedb0555cff1559 | — | |
hashd2a98fe01257d897a0dc5994392cbde9089fadf9 | — | |
hash39368a9465aca3286e4436650b7a33b39a9294a81f3e681e056c9da0550e27c4 | — | |
hash9839448acc050331b5713882a25b863b47993a0f2859b4820563e34c72f5b679 | — |
Threat ID: 6ab14dea55bf5e2cf5168606
Added to database: 09/21/2026, 15:31:54 UTC
Last enriched: 09/21/2026, 15:47:24 UTC
Last updated: 09/21/2026, 18:45:41 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.