Intrusion setG0108
Blue Mockingbird
Blue Mockingbird is a cluster of observed activity involving Monero cryptocurrency-mining payloads in dynamic-link library (DLL) form on Windows systems. The earliest observed Blue Mockingbird tools were created in December 2019.
- Documented techniques
- 22
- Basis
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, grouped by the stage of an attack they belong to. This is the actionable half: each one is a behaviour you can look for in your own logs, and a control you can test.
resource development1
initial access1
execution5
persistence1
privilege escalation1
credential access1
discovery1
lateral movement2
command and control1
impact1
defense impairment1
Tools
Legitimate or dual-use software the group is documented using. Most of it is software your own administrators use too, which is the point.
FRPMimikatz