From Registry-Stored PowerShell to In-Memory Cryptocurrency Mining: A Multi-Stage Infection Chain
released on 2026-09-21 @ 03:16:13 PM
A sophisticated multi-stage infection chain was discovered through analysis of a system exhibiting frequent PowerShell execution alerts. The attack leveraged multiple layers of obfuscation and concealment techniques, including Registry-based payload storage, DNS TXT record exploitation, and data hidden within image and WAV audio files. The threat actors employed various evasion methods such as security control tampering and in-memory execution to avoid detection. Rather than writing payloads directly to disk, attackers reconstructed malicious code from distributed sources including Registry entries and steganographically encoded data in media files. The ultimate objective of this elaborate infection chain was to deploy cryptocurrency mining operations covertly on compromised systems while maintaining persistent access through multiple redundant mechanisms.