REF4578 is an unattributed financially motivated cryptomining intrusion set tracked for deploying the GHOSTENGINE malware framework, portions of which are also known as HIDDENSHOVEL. Its objective is to install and maintain XMRig for Monero mining while suppressing endpoint defenses. The operation uses a masqueraded Windows executable to launch a PowerShell-based loader that retrieves modular components and configuration data. GHOSTENGINE disables Microsoft Defender, clears Windows event logs, identifies installed EDR products, and uses vulnerable kernel drivers to terminate EDR processes and remove their binaries. It also employs a redundant in-memory security-tool termination component. Persistence is established through recurring scheduled tasks and phantom-DLL loading. A PowerShell backdoor supports encoded command exchange and remote command execution. The framework uses multiple download and command-and-control transfer mechanisms and can remove artifacts associated with earlier infections. No threat actor, source country, victim organization, or targeted country has been publicly attributed with high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
25 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
19 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cryptojacking intrusion set that disables EDR/security tools using vulnerable drivers, establishes persistence, deploys a backdoor, and installs the XMRig Monero miner.
Intrusion set conducting a cryptomining campaign using GhostEngine/Hidden Shovel to disable EDR, establish persistence, install a backdoor, and deploy XMRig for Monero mining.
A cryptomining intrusion set deploying the GHOSTENGINE payload to disable endpoint security products, establish redundant persistence, provide a PowerShell backdoor, and run a persistent Monero miner.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.