Hackers Hide XMRig Miner in Windows Registry, PNG and WAV Files to Evade Detection
K7 Security Labs discovered a multi-stage Windows malware chain hiding an XMRig miner in the Registry, PNG, and WAV files.
K7 Security Labs analysts investigated repeated PowerShell alerts and uncovered a layered infection that stores encoded PowerShell in a Registry value, uses DNS TXT lookups to retrieve a PNG container whose red pixel channel hides a script, and downloads WAV files (Atsg.wav, Tmav.wav, Realtek HD Audio.wav) that carry encoded stages and .NET assemblies. The chain tampers with Defender exclusions and execution policy, establishes persistence via scheduled tasks and WMI event subscriptions, and loads an XMRig RandomX miner entirely in memory, aided by the signed WinRing0.sys driver. The active C2 channel could allow operators to deliver additional payloads beyond cryptomining.