A new fileless miner dubbed CoinMiner appeared in the wild, it uses NSA EternalBlue exploit and WMI tool to spread. A new strain of Cryptocurrency Miner has been identified and is hard to detect and infects Windows PCs via EternalBlue NSA exploit. The combination of fileless WMI and EternalBlue makes this threat extremely stealthy and persistent reads the analysis published by Trend Micro. Users should check they have installed the MS17-010 Microsoft security patch, or disable the SMBv1 protocol on their systems.”]
Source: https://securityaffairs.co/wordpress/62254/cyber-crime/fileless-miner-coinminer.html

