Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Blue Mockingbird

Description

Blue Mockingbird is a cluster of observed activity involving Monero cryptocurrency-mining payloads in dynamic-link library (DLL) form on Windows systems. The earliest observed Blue Mockingbird tools were created in December 2019.(Citation: RedCanary Mockingbird May 2020)

AI Analysis

· 2 months ago

Executive Summary

Blue Mockingbird is a threat actor cluster observed for its involvement in Monero cryptocurrency-mining activities utilizing dynamic-link library (DLL) payloads on Windows systems. This actor has been active since December 2019 and has been linked to various techniques and tools. The primary motivation and goals of Blue Mockingbird are still unclear, but its tactics, techniques, and procedures (TTPs) suggest a focus on exploiting Windows systems for cryptocurrency mining.

Goals & Targeting

Blue Mockingbird's strategic objectives appear to revolve around exploiting Windows systems for cryptocurrency mining, suggesting a primary goal of financial gain. The targeting profile indicates a focus on sectors or countries with potentially vulnerable Windows systems, although the specific sectors or countries targeted are not clearly defined. Typical victims could include any organization or individual with insecure Windows systems, though the actor may prefer targets with significant computational resources.

Enhanced Description

Blue Mockingbird is characterized by its employment of Monero cryptocurrency-mining payloads in DLL form on Windows systems. The earliest tools associated with this actor were developed in December 2019. This actor's activities have been linked to various ATT&CK techniques, including the use of scheduled tasks, registry modifications, and exploitation of public-facing applications. The utilization of tools like FRP and Mimikatz further suggests an actor capable of manipulating system resources and credentials for its nefarious activities.

Key Capabilities

  • Exploitation of Windows systems
  • Use of cryptocurrency-mining malware
  • Employment of tools for credential manipulation and system access
  • Ability to evade detection through various TTPs

MITRE ATT&CK Tactics

Execution
Persistence
Privilege Escalation
Defense Evasion
Discovery
Lateral Movement
Command and Control

ATT&CK Techniques

T1053.005
T1574.012
T1036.005
T1190
T1112
T1003.001
T1059.001
T1588.002
T1496.001
T1059.003
T1134
T1021.001
T1047
T1218.011
T1027.013
T1543.003
T1082
T1021.002
T1090
T1546.003
T1218.010

Software / Tooling

FRP
Mimikatz

Campaigns & Victims

The campaign patterns of Blue Mockingbird suggest a continued focus on exploiting Windows systems for cryptocurrency mining. The operational tempo of this actor has been consistent since its first observation in December 2019, indicating a steady effort to compromise vulnerable systems. Notable past operations include the deployment of Monero cryptocurrency-mining payloads via DLLs, and the use of tools like FRP and Mimikatz for system exploitation and credential manipulation.

IOC Patterns

  • DLL-based Monero cryptocurrency-mining payloads
  • Use of Scheduled Tasks for persistence
  • Registry modifications for evasion and persistence
  • Exploitation of public-facing applications

Recommended Actions

  • Implement robust system and network monitoring to detect unusual activity
  • Regularly update and patch Windows systems and software
  • Use antivirus software and keep it up-to-date
  • Limit user privileges and enforce the principle of least privilege
  • Use two-factor authentication for all remote access

Suggested Tags

Cryptocurrency Mining
Windows Exploitation
System Compromise
Evasion Techniques

Confidence Assessment

The confidence level in the available data on Blue Mockingbird is moderate, based on the observed activities and linked intelligence. However, there is a lack of clear information on the actor's primary motivation, type, and the full scope of its targeting profile, which introduces uncertainty. Further intelligence gathering is necessary to fully understand the capabilities and objectives of this threat actor.

ATT&CK Techniques

Execution
5 techniques
Stealth
6 techniques

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. RedCanary Mockingbird May 2020 — Lambert, T. (2020, May 7). Introducing Blue Mockingbird. Retrieved May 26, 2020.

Intel Summary

22

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

12

Tactics

Tags

Financial Targeting
Cryptocurrency Mining
Windows Exploitation
System Compromise
Evasion Techniques

Details

MITRE ID
G0108
Type
Unknown
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--73a80fab-2aa3-48e0-a4d0-3a4828200aee
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.