A fileless attack is leveraging PCASTLE to distribute samples of XMRig, a well-known Monero-mining malware family. Trend Micro first observed the campaign on May 17 when it spotted a series of attacks targeting systems based in China. The attacks used a scheduled task or RunOnce registry key to download the first-stage. script to download, execute and save a. PowerShell command as a. scheduled task. At this point, an obfuscated. script was used to download and execute the attacks second-stage PowerShell script.”]