#InMemoryLoad
Multi-stage intrusion used Registry-stored PowerShell, DNS TXT records, PNG and WAV payloads, and in-memory .NET loading to deploy XMRig mining while weakening Defender and PowerShell logging. #XMRig #RegistryHiding #InMemoryLoad
From Registry-Stored PowerShell To In-Memory Cryptocurrency Mining: A Multi-Stage Infection Chain
Researchers analyzed a multi-stage infection that used Registry-stored PowerShell, DNS TXT records, PNG and WAV file payload containers, and in-memory .NET loading to hide its activity. The chain ultimately deployed an XMRig-based cryptocurrency miner while maintaining a separate C2 channel and weakening Microsoft Defender and PowerShell logging controls. #XMRig #WinRing0.sys #RealtekHDAudio.wav #sslvalidcert.com #httptls.org
www.hendryadrian.com
September 18, 2026 at 7:45 AM