Malik, M. (2019, June 20). LoudMiner: Cross-platform mining in cracked VST software. Retrieved May 18, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareLoudMiner | LoudMiner used a script to gather the IP address of the infected machine before sending to the C2. |
| T1027.010 Command Obfuscation |
MalwareLoudMiner | LoudMiner has obfuscated various scripts. |
| T1027.013 Encrypted/Encoded File |
MalwareLoudMiner | LoudMiner has encrypted DMG files. |
| T1057 Process Discovery |
MalwareLoudMiner | LoudMiner used the |
| T1059.003 Windows Command Shell |
MalwareLoudMiner | LoudMiner used a batch script to run the Linux virtual machine as a service. |
| T1059.004 Unix Shell |
MalwareLoudMiner | LoudMiner used shell scripts to launch various services and to start/stop the QEMU virtualization. |
| T1070.004 File Deletion |
MalwareLoudMiner | LoudMiner deleted installation files after completion. |
| T1082 System Information Discovery |
MalwareLoudMiner | LoudMiner has monitored CPU usage. |
| T1105 Ingress Tool Transfer |
MalwareLoudMiner | LoudMiner used SCP to update the miner from the C2. |
| T1189 Drive-by Compromise |
MalwareLoudMiner | LoudMiner is typically bundled with pirated copies of Virtual Studio Technology (VST) for Windows and macOS. |
| T1218.007 Msiexec |
MalwareLoudMiner | LoudMiner used an MSI installer to install the virtualization software. |
| T1496.001 Compute Hijacking |
MalwareLoudMiner | LoudMiner harvested system resources to mine cryptocurrency, using XMRig to mine Monero. |
| T1543.003 Windows Service |
MalwareLoudMiner | LoudMiner can automatically launch a Linux virtual machine as a service at startup if the AutoStart option is enabled in the VBoxVmService configuration file. |
| T1543.004 Launch Daemon |
MalwareLoudMiner | LoudMiner adds plist files with the naming format |
| T1564.001 Hidden Files and Directories |
MalwareLoudMiner | LoudMiner has set the attributes of the VirtualBox directory and VBoxVmService parent directory to "hidden". |
| T1564.006 Run Virtual Instance |
MalwareLoudMiner | LoudMiner has used QEMU and VirtualBox to run a Tiny Core Linux virtual machine, which runs XMRig and makes connections to the C2 server for updates. |
| T1569.001 Launchctl |
MalwareLoudMiner | LoudMiner launched the QEMU services in the |
| T1569.002 Service Execution |
MalwareLoudMiner | LoudMiner started the cryptomining virtual machine as a service on the infected machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.