Blue Mockingbird is a cluster of observed activity involving Monero cryptocurrency-mining payloads in dynamic-link library (DLL) form on Windows systems. The earliest observed Blue Mockingbird tools were created in December 2019.(Citation: RedCanary Mockingbird May 2020)
Executive Summary
Blue Mockingbird is a threat actor cluster observed for its involvement in Monero cryptocurrency-mining activities utilizing dynamic-link library (DLL) payloads on Windows systems. This actor has been active since December 2019 and has been linked to various techniques and tools. The primary motivation and goals of Blue Mockingbird are still unclear, but its tactics, techniques, and procedures (TTPs) suggest a focus on exploiting Windows systems for cryptocurrency mining.
Goals & Targeting
Blue Mockingbird's strategic objectives appear to revolve around exploiting Windows systems for cryptocurrency mining, suggesting a primary goal of financial gain. The targeting profile indicates a focus on sectors or countries with potentially vulnerable Windows systems, although the specific sectors or countries targeted are not clearly defined. Typical victims could include any organization or individual with insecure Windows systems, though the actor may prefer targets with significant computational resources.
Enhanced Description
Blue Mockingbird is characterized by its employment of Monero cryptocurrency-mining payloads in DLL form on Windows systems. The earliest tools associated with this actor were developed in December 2019. This actor's activities have been linked to various ATT&CK techniques, including the use of scheduled tasks, registry modifications, and exploitation of public-facing applications. The utilization of tools like FRP and Mimikatz further suggests an actor capable of manipulating system resources and credentials for its nefarious activities.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The campaign patterns of Blue Mockingbird suggest a continued focus on exploiting Windows systems for cryptocurrency mining. The operational tempo of this actor has been consistent since its first observation in December 2019, indicating a steady effort to compromise vulnerable systems. Notable past operations include the deployment of Monero cryptocurrency-mining payloads via DLLs, and the use of tools like FRP and Mimikatz for system exploitation and credential manipulation.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the available data on Blue Mockingbird is moderate, based on the observed activities and linked intelligence. However, there is a lack of clear information on the actor's primary motivation, type, and the full scope of its targeting profile, which introduces uncertainty. Further intelligence gathering is necessary to fully understand the capabilities and objectives of this threat actor.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
22
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
12
Tactics