Malware that uses the CPU resources of an infected system to “mine” cryptocurrency for the creator of the malware. It copies itself to C:\ProgramData\MicrosoftCorporation\Windows\SystemData\Isass.exe and adds itself to the list of startup items. Updates to the malware, as well as the creator’s credentials needed for mining, are automatically downloaded from a server.
Geographical distribution of attacks by the Trojan.Win32.DiscordiaMiner family
Countries with most attacked users (% of total attacks)
* Percentage among all unique Kaspersky users worldwide attacked by this malware