Cybercriminals are pushing a new wave of USB-based CoinMiner infections across South Korea. The campaign hides malicious scripts inside disguised shortcut files that look harmless at first glance. Infected systems silently install XMRig to mine Monero and adjust power settings to keep machines active for long stretches. The method is simple enough that users rarely notice anything wrong until performance drops or security tools flag suspicious activity.
Relevant Source (AhnLab Security Intelligence Center): CoinMiner Malware Being Continuously Distributed via USB
AhnLab’s report describes CoinMiner campaigns in South Korea that spread via infected USB drives using a USB Drive.lnk shortcut, hidden sysvolume folders, and XMRig-based mining, which aligns directly with the tactics outlined in this section.
Quick Facts
- Attack spreads through infected USB drives using deceptive shortcut files
- Malware chain uses VBS, BAT, and DLL components to install XMRig
- Hidden “sysvolume” folder stores the malicious payloads
- BAT scripts modify Windows Defender exclusions to reduce detection
- Miner shuts down when games or monitoring tools run
- Campaign aligns with DIRTYBULK and CUTFAIL activity reported in 2025
USB Shortcut Malware Spread
Threat actors rely on shortcut files that mimic normal USB content. When users click the “USB Drive.lnk” file, a VBS script launches the malware chain while also opening a folder with their real files. The infection blends into normal activity because the user sees expected content while the attackers install XMRig in the background. These scripts copy and rename the payload as a DLL and load it with the legitimate printui.exe program for stealth.
- Scripts add Windows Defender exclusion paths
- A disguised System32 folder helps avoid security scans
- The dropper registers persistence under the DcomLaunch service
This setup lets the miner stay active even after reboots. USB campaigns remain effective because they rely on simple user actions instead of network flaws.
Relevant Source (CERT Coordination Center): Microsoft Windows Automatically Executes Code Referenced by Shortcut
This advisory describes how malicious Windows shortcut (.LNK) files can execute attacker-controlled DLLs from removable media, directly mirroring the shortcut-based USB infection method outlined in this section.
How CoinMiner Malware Hurts Performance
CoinMiner infections drain CPU resources and reduce workstation performance. XMRig receives encrypted configuration files from command-and-control servers and starts mining Monero using up to half of the CPU. The malware prevents sleep mode and shifts behavior when users open games or monitoring utilities. This tactic limits suspicion and keeps mining activity under the radar.
- Reduced system responsiveness during mining
- Avoids detection by terminating when Task Manager opens
- Uses TLS connections to remote servers
- Operates quietly through renamed system DLLs
- Leverages persistence that survives reboots
Stealth and resource control give attackers a reliable path to long-term mining profits. These traits also make infections harder for casual users to spot.
Relevant Source (Check Point Research): XMRig Malware
Check Point describes how XMRig-based cryptomining malware hijacks CPU resources, slows systems, and runs stealthily in the background, matching the performance and stealth impacts outlined in this section.
Practical Steps To Block USB Malware
A few basic steps help block USB-based malware and reduce risk. Security teams should disable autorun features and restrict USB device usage when possible. Users should avoid running shortcut files from unknown drives and scan removable media before opening anything. Organizations should tighten Defender policies to prevent exclusion list tampering.
- Disable USB autorun
- Enforce scans on all removable drives
- Lock down Defender settings with administrative controls
- Monitor for unusual DLL registrations
- Search endpoints for renamed printui.dll files
A proactive posture helps prevent these infections from gaining persistence. Routine scans and baseline monitoring give teams a better chance at catching early signs.
Relevant Source (CISA): Using Caution with USB Drives
CISA outlines practical steps such as disabling Autorun, limiting removable media use, and scanning USB drives to reduce the risk of malware infections from portable devices.
Global USB Malware Trend
USB-delivered malware continues to succeed because it bypasses many of the technical controls designed for network-only threats. Attackers take advantage of user trust and simple curiosity when opening files on removable drives. These infections spread quietly across shared machines and unmanaged workstations.
Security researchers note that DIRTYBULK and CUTFAIL activity rose throughout 2025, and the shift toward refined USB attacks fits that pattern. The latest CoinMiner strain shows careful design choices that prioritize stealth and persistence. That combination keeps attackers profitable even when defenses improve.
Relevant Source (Mandiant / Google Cloud): The Spies Who Loved You: Infected USB Drives to Steal Secrets
Mandiant documents a sharp rise in USB-delivered malware campaigns that bypass traditional network-focused defenses and use removable drives for long-lived, stealthy infections across sectors.
Breaking Risky USB Habits
Businesses and personal users share the same exposure when USB devices circulate freely. Clear policies, consistent scanning, and simple user training can stop most of these infections before they start. The rising use of disguised shortcut files shows that attackers rely on predictable habits, so breaking those habits is the strongest defense.
Relevant Source (UK National Cyber Security Centre): 10 Steps: Removable Media Controls
NCSC highlights how clear policies, controlled use of removable media, and ongoing user awareness reduce malware risk from USB devices.
FAQ
What triggers the CoinMiner infection?
The infection starts when a user opens a deceptive shortcut file on an infected USB drive.
Why does the malware use multiple script types?
Each script handles a specific task such as launching payloads, adjusting Defender settings, and loading the miner DLL through trusted Windows components.
How does the malware stay hidden?
It opens the user’s real files, runs silently in the background, and stops mining when monitoring tools appear.
Can antivirus tools detect it?
Yes, but detection is harder when attackers add Defender exclusions and hide payloads in renamed folders.
How do I check if my system is infected?
Inspect unusual DLL registrations, look for renamed printui.dll files, watch for unexplained CPU spikes, and scan connected USB drives.
JENI Systems And Smarter Security Maintenance
Threat campaigns that rely on USB-based malware succeed when systems drift out of tune. JENI reduces that risk by keeping machines stable, clean, and predictable. A well-maintained system makes it harder for threats like hidden miners and renamed DLL payloads to blend in.
How JENI Strengthens System Integrity:
- Cleans deep caches, logs, temp files, and clutter that attackers often exploit
- Repairs core macOS and Windows components that malware targets for persistence
- Produces clear HTML reports that highlight unusual system behavior
A healthier machine gives users a better chance of noticing abnormal performance drops or suspicious background activity associated with attacks like USB-borne CoinMiner infections. JENI keeps systems running consistently and reduces opportunities for stealthy payloads to hide behind corrupted caches or misconfigured services. The more predictable the system, the harder it is for malware processes to mask themselves. JENI helps maintain that predictability without cloud activity, tracking, or noise.

