GhostEngine, also known as Hidden Shovel, is a Windows-based modular cryptomining malware framework associated with the REF4578 intrusion set. It is designed to deploy and maintain XMRig for Monero mining while suppressing endpoint defenses. The framework uses a masqueraded executable and PowerShell-based loader to retrieve modules and configuration data over HTTP, with fallback infrastructure and FTP support. Its components can disable Microsoft Defender, clear Windows event logs, remove remnants of earlier infections, enable remote services, and establish redundant scheduled-task and DLL-based persistence.
GhostEngine identifies installed EDR products and abuses vulnerable third-party kernel drivers to terminate EDR processes and delete their binaries, constituting bring-your-own-vulnerable-driver activity. A redundant memory-resident component continuously monitors for and terminates security processes. The framework also includes a PowerShell backdoor that exchanges encoded system information and commands with command-and-control infrastructure, enabling remote command execution. Its operators have not been publicly identified, and no specific victim organizations or industries have been confirmed.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
GHOSTENGINE is responsible for retrieving and executing modules on the machine. It primarily uses HTTP to download files from a configured domain, with a backup IP in case domains are unavailable. Additionally, it employs FTP as a secondary protocol with embedded credentials.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Detection rules and behavior prevention events associated with the campaign include the following: ... local scheduled task creation
get.png creates SYSTEM scheduled tasks named OneDriveCloudSync, DefaultBrowserUpdate, and OneDriveCloudBackup to execute oci.dll, re-download get.png, and run smartsscreen.exe.
It also includes a PowerShell script that functions like a backdoor, enabling remote command execution on the system.
Tiworker.exe executes a hardcoded PowerShell command to retrieve the obfuscated get.png script; get.png orchestrates module download and execution.
Detection rules and behavior prevention events associated with the campaign include the following: ... local scheduled task creation
Detection rules and behavior prevention events associated with the campaign include the following: ... local scheduled task creation
get.png creates SYSTEM scheduled tasks named OneDriveCloudSync, DefaultBrowserUpdate, and OneDriveCloudBackup to execute oci.dll, re-download get.png, and run smartsscreen.exe.
the researchers recommended that organizations prioritize the detection and prevention of these initial actions ... including: ... elevating privileges to system integrity
The intrusion begins with a PE named Tiworker.exe, masquerading as the legitimate Windows TiWorker.exe file.
get.png clears Application, Security, Setup, System, Forwarded Events, and several Microsoft-Windows operational event-log channels.
clearn.png removes prior campaign artifacts and scheduled tasks; get.png clears Windows Temp, Windows Logs, $Recycle.Bin, and a trace file, and can delete large files to create storage space.
GHOSTENGINE primarily uses HTTP to download files from a configured domain; backup.png sends encoded host information and command results while awaiting commands.
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously undocumented multimodule malware used in a cryptomining campaign. It leverages vulnerable drivers to terminate and delete EDR agents, attempts to disable Windows Defender and clear event logs, establishes persistence, downloads additional modules, installs a backdoor for remote command execution, and deploys a miner while evading detection.
A multi-component malware framework used to disable EDR/security tools via vulnerable drivers, establish persistence, deploy a PowerShell backdoor, and install a Monero crypto miner.
A modular Windows malware framework used by REF4578 to establish persistence, disable Windows Defender and event logging, terminate and delete EDR agents through abused vulnerable drivers, deploy an in-memory EDR-killing component, provide a PowerShell remote-command backdoor, and download and execute the XMRig Monero miner.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.