216.73.216.6

From Scripts to Systems: A Comprehensive Look at Tangerine Turkey Operations

· Published 29/10/2025 18:37 · Modified 29/10/2025 20:19

Export JSON

Essential information

Published
29/10/2025 18:37
Modified
29/10/2025 20:19
Tags
2025-10-29 cryptomining defense evasion living-off-the-land persistence usb vbscript worm xmrig
Related entities
3 observables, 1 intrusion sets (apt), 7 techniques (mitre)

Description

Tangerine Turkey is a campaign that uses worms to spread via drives, leveraging binaries for execution and . The group employs techniques by modifying registry keys and masquerading malicious binaries as legitimate system files. Their primary goal is financial gain through unauthorized cryptocurrency mining. The malware creates a mock directory to hide its activity, establishes through malicious services and scheduled tasks, and attempts to disable Windows Defender. While currently focused on , the actor's ability to achieve and move laterally poses broader security risks.

External references