This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication it is unclear how XIAOBA is delivered to a target device. Once installed, it will begin to inject the Coinhive mining script into all .html and .htm files. Other variants have been observed using the XMRig miner instead of Coinhive. Alongside this, XIAOBA will execute a version of itself in the startup folder and delete registry entries to disable safe boot mode.
XIAOBA will also traverse all available directories and corrupt any files with the extensions .exe, .com, .scr and .pif; prepending the files once done. This is the only check it does, meaning files can be infected multiple times. Critical system files are not excluded from this search and if corrupted will render the device inoperable.
Remediation advice
To prevent and detect an infection, ensure that:Remediation steps
| Type | Step |
|---|---|
|
Last edited: 17 February 2020 12:58 pm