Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Returned Libra

Also known as: 8220 Mining Group

Description

Returned Libra, also known as 8220 Mining Group, is a cloud threat actor group that has been active since at least 2017. Tools commonly employed during their operations are PwnRig or DBUsed which are customized variants of the XMRig Monero mining software. The Returned Libra mining group is believed to have originated from a GitHub fork of the Rocke group's software. Returned Libra has elevated its mining operations with the use of cloud service platform credential scrapping.

AI Analysis

· 1 week ago

Executive Summary

Returned Libra, also known as the 8220 Mining Group, is a cloud-based threat actor group suspected to originate from a GitHub fork of the Rocke group's software. They have been active since at least 2017 and specialize in cryptojacking using customized XMRig variants like PwnRig and DBUsed. Their operations involve scraping cloud service credentials to deploy mining activities, targeting sectors with high cloud infrastructure usage to maximize revenue from cryptocurrency mining.

Goals & Targeting

Returned Libra's primary motivation appears to be financial gain through unauthorized cryptocurrency mining. They target industries with substantial cloud infrastructure, as these environments provide ample processing power for mining operations. Their targeting strategy focuses on sectors where the detection of mining activities is less likely, such as educational institutions, healthcare providers, and government agencies. The group's ability to scrape cloud credentials allows them to scale their operations effectively, leading to significant financial losses for victims due to increased infrastructure costs and potential data breaches.

Enhanced Description

Returned Libra operates as a sophisticated cyber threat group focused on illegal cryptocurrency mining through cloud-based platforms. The group's primary tools include PwnRig and DBUsed, which are customized versions of the XMRig Monero mining software. These tools are designed to operate covertly within compromised cloud environments, often using credential scraping techniques to gain access to high-value targets. Returned Libra's operational strategy involves targeting industries with significant cloud service usage, such as technology, finance, and healthcare, where their activities can remain undetected for extended periods. The group's association with the Rocke group suggests potential links to larger cybercriminal or state-sponsored operations. Their use of GitHub repositories indicates an interest in community-driven tool development, which may allow them to evolve quickly and maintain a low profile.

Key Capabilities

  • Customized XMRig variants (PwnRig, DBUsed)
  • Cloud service credential scraping
  • Use ofaaS platforms for distributed mining operations
  • Persistent駐留 within compromised environments
  • sophisticated evasion techniques

MITRE ATT&CK Tactics

Initial Access
Defense Evasion
Execution

ATT&CK Techniques

T1025.003
T1685
T1496

Software / Tooling

PwnRig
DBUsed
XMRig
Custom Cloud Credential Scraping Tools

Campaigns & Victims

Returned Libra has been linked to multiple long-term campaigns targeting cloud service providers and their clients. Their operations typically involve a prolonged驻留 within targeted networks, with minimal disruptive activity to avoid detection. Notable patterns include theuse of legitimate cloud platforms for mining infrastructure, as well as thestealthy exfiltration of credentials for future use._past campaigns have been observed in Asia-Pacific and Europe, suggesting a global targeting strategy.

IOC Patterns

  • Use of XMRig-based miners with specific configuration strings
  • Beaconing communication to command-and-control (C2) servers
  • Unusual spikes in CPU usage on cloud instances
  • Presence of custom scripts for credential scraping
  • Abnormal network traffic patterns indicative of mining operations

Recommended Actions

  • Implement multi-factor authentication for cloud service accounts
  • Monitor for unauthorized cryptocurrency mining activity
  • Regularly update and patch cloud infrastructure software
  • Train employees to recognize phishing attempts targeting cloud credentials
  • Conduct thorough logging reviews for signs of credential scraping
  • Deploy a SIEM solution to detect异常 IOC patterns
  • Engage with threat intelligence feeds to identify emerging threats

Suggested Tags

APT group
Cyber Espionage
Cryptojacking
Cloud Threats
Financial Crime
State-sponsored

Confidence Assessment

Low confidence due to limited public reporting on Returned Libra's activities. While the group's operational手法 are relatively well-documented, their exact origins and motives remain unclear. There is no definitive evidence of state sponsorship or direct links to other threat groups beyond the Rocke association. Additional intelligence regarding their campaign patterns and受害者的完整列表 would enhance understanding.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT group
Cyber Espionage
Cryptojacking
Cloud Threats
Financial Crime
State-sponsored

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.