Darktrace Uncovers Stealthy Cryptojacking Campaign Bypassing Windows Defender
Cybersecurity firm Darktrace has detected a sophisticated cryptojacking operation targeting Windows systems, leveraging PowerShell and AutoIt scripting to evade detection by Windows Defender. The campaign deploys NBminer to hijack processing power for cryptocurrency mining.
Attackers execute malicious scripts directly in system memory, rendering traditional antivirus scans ineffective. The multi-stage infection chain, active since late July, demonstrates increasing sophistication in cryptojacking techniques as attackers exploit legitimate Windows tools for illicit gain.