New technical analysis of Tangerine Turkey - a sophisticated cryptomining operation spreading via USB and abusing Windows LOLBins.
Key Findings:
- USB VBS dropper with worm capabilities
- LOLBin abuse (printui.exe)
- Multi-stage persistence
- XMRig miner payload
My Contribution:
Developed custom Yara rule detecting:
- VBS/BAT components
- Service creation
- Defender evasion
- Known IOCs
Practical detection for SOC teams against this emerging threat.
#MalwareAnalysis #CyberSecurity #YaraRules #ThreatHunting
[link] [comments]






![The Gang Republic: Inside Haiti’s New Order (2026) - ~3 million people living in the grips of all-out gang war. France24 spent a fortnight filming in and around the Haitian capital, speaking to a population held hostage by this drawn-out crisis (CC) [00:52:38]](https://external-preview.redd.it/0j1B98qWy2MAsjLEwjT10EbknBToMVuWRJ-tUeZsTso.jpeg?width=320&crop=smart&auto=webp&s=041d55dee546ef807e7eda2e0d1d013111f02a25)

English (US) ·