Papers1 provider · 1 record
January 15, 2024· arXiv
preprint
Open access

The Pulse of Fileless Cryptojacking Attacks: Malicious PowerShell Scripts

Authors:Said VarliogluNelly ElsayedEva Ruhsar VarliogluMurat OzerZag ElSayed

Abstract

Fileless malware predominantly relies on PowerShell scripts, leveraging the native capabilities of Windows systems to execute stealthy attacks that leave no traces on the victim's system. The effectiveness of the fileless method lies in its ability to remain operational on victim endpoints through memory execution, even if the attacks are detected, and the original malicious scripts are removed. Threat actors have increasingly utilized this technique, particularly since 2017, to conduct cryptojacking attacks. With the emergence of new Remote Code Execution (RCE) vulnerabilities in ubiquitous libraries, widespread cryptocurrency mining attacks have become prevalent, often employing fileless techniques. This paper provides a comprehensive analysis of PowerShell scripts of fileless cryptojacking, dissecting the common malicious patterns based on the MITRE ATT&CK framework.

Community

0 comments
Use Connect Wallet in the navigation

No discussion yet

Be the first to share a question or observation.