PrintMiner is a Windows cryptocurrency-mining malware family observed in a USB-borne campaign documented by AhnLab in 2025 and associated by Mandiant with the broader DIRTYBULK/CUTFAIL attack series. The infection chain uses a malicious removable-drive shortcut file named "USB Drive.lnk" that launches VBS and BAT scripts, hides the victim’s original files, and abuses DLL side-loading by placing a malicious "printui.dll" next to a legitimate "printui.exe" in a deceptive "C:\Windows \System32" path. The staged droppers create and execute additional components including "%SystemDirectory%\svcinsty64.exe" and "%SystemDirectory%\svctrl64.exe", after which a DLL is registered with the DcomLaunch service for persistence; the malware executed through that service is categorized as PrintMiner. PrintMiner adds its installation path as a Windows Defender exclusion, changes power settings to keep the host from sleeping, discovers its C2 server, and transmits host profiling data including CPU and GPU information. It installs additional encrypted payloads, including XMRig, into "%SystemDirectory%\wsvcz" and updates "%SystemDirectory%\wsvcz\wlogz.dat" with the C2 IP, mining information, and installed malware paths. It also propagates via USB by recreating the malicious shortcut and worm components and moving user files into a hidden folder structure. Before launching XMRig, it checks for process-monitoring tools such as Process Explorer, TaskMgr, System Informer, and Process Hacker, and also checks for numerous game client processes, likely to reduce user suspicion or performance impact. The campaign mined Monero using XMRig and was reported using the pool "r2.hashpoolpx[.]net" over port 443 with TLS. Reported network indicators include 2[.]58[.]56[.]13, r2[.]hashpoolpx[.]net, and umnsrx[.]net.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The VBS malware is responsible for executing BAT malware with the same name (“u643257.bat”) in the same directory.
The thread responsible for executing XMRig examines the currently running processes, and only executes XMRig when specific processes are not running, then terminates XMRig when it is already running. Among the processes examined, there are process inspection tools such as Process Explorer, TaskMgr, System Informer, and Process Hacker.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware component used to install cryptocurrency miners (including XMRig) on infected systems, often delivered via USB drives.
A coin-mining malware family propagated via infected USB drives using LNK/VBS/BAT stages and DLL side-loading through printui.exe. It establishes persistence via the DcomLaunch service, adds Defender exclusions, modifies power settings, reports host profiling data to C2, updates local configuration, spreads through USB, and deploys XMRig to mine Monero while attempting to evade user notice and process inspection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.