#WinRing0sys
This miner never writes a file - it lives in the Registry and hides its C2 in a PNG and WAV. https://intel.threadlinqs.com/threat/TL-2026-2593 #ThreatIntel #CVE_2020_14979 #xmrig #WinRing0sys
September 20, 2026 at 11:31 PM
📢 Chaîne d'infection multi-étapes : PowerShell en registre vers minage crypto en mémoire

Analyse publiée le 18 septembre 2026 par K7 Computing Labs (https://labs.k7computing.com), suite à l'investigation d'un système…

🟡 vérification factuelle moyenne
#PowerShell #WinRing0Sys #Cyberveille
Chaîne d'infection multi-étapes : PowerShell en registre vers minage crypto en mémoire
Analyse publiée le 18 septembre 2026 par K7 Computing Labs (https://labs.k7computing.com), suite à l'investigation d'un système présentant des alertes fréquentes liées à des exécutions PowerShell.
cyberveille.ch
September 21, 2026 at 12:30 AM