Tangerine Turkey is a financially motivated cryptomining threat campaign centered on a VBScript worm that propagates through removable drives and deploys XMRig-based cryptocurrency mining payloads. The operation uses batch scripts, Visual Basic Script, and Windows living-off-the-land binaries to execute, persist, and evade defenses on compromised systems. Observed tradecraft includes execution through script interpreters, DLL sideloading via legitimate Windows utilities, masquerading of malicious components as system files, obfuscated PowerShell, Microsoft Defender exclusion changes, scheduled-task creation, and malicious Windows service installation. The campaign also performs cleanup and anti-analysis actions after staging payloads. Tangerine Turkey has been observed using infected USB media for initial access and lateral spread, making removable-drive propagation a defining characteristic of the activity. After execution, the malware stages components in deceptive directories, abuses legitimate binaries to load malicious libraries, and installs a coin miner for unauthorized cryptocurrency mining, commonly associated with Monero. Reporting indicates the campaign emerged in late 2024 and expanded globally across multiple industries and geographies. No high-confidence association with ransomware activity is established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tangerine Turkey is a campaign deploying XMRig miners via infected USB devices, using batch and VB scripts for persistence and evasion.
USB-borne VBScript worm campaign used for lateral spread via removable media, persistence (service + scheduled task), defense evasion (Defender exclusions, masqueraded directories), and deployment of cryptomining payloads (notably XMRig) for financial gain.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.