Malware.View on attack.mitre.org
LoudMiner is a cryptocurrency miner which uses virtualization software to siphon system resources. The miner has been bundled with pirated copies of Virtual Studio Technology (VST) for Windows and macOS.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
LoudMiner used a script to gather the IP address of the infected machine before sending to the C2. |
| T1027.010 Command Obfuscation |
LoudMiner has obfuscated various scripts. |
| T1027.013 Encrypted/Encoded File |
LoudMiner has encrypted DMG files. |
| T1057 Process Discovery |
LoudMiner used the |
| T1059.003 Windows Command Shell |
LoudMiner used a batch script to run the Linux virtual machine as a service. |
| T1059.004 Unix Shell |
LoudMiner used shell scripts to launch various services and to start/stop the QEMU virtualization. |
| T1070.004 File Deletion |
LoudMiner deleted installation files after completion. |
| T1082 System Information Discovery |
LoudMiner has monitored CPU usage. |
| T1105 Ingress Tool Transfer |
LoudMiner used SCP to update the miner from the C2. |
| T1189 Drive-by Compromise |
LoudMiner is typically bundled with pirated copies of Virtual Studio Technology (VST) for Windows and macOS. |
| T1218.007 Msiexec |
LoudMiner used an MSI installer to install the virtualization software. |
| T1496.001 Compute Hijacking |
LoudMiner harvested system resources to mine cryptocurrency, using XMRig to mine Monero. |
| T1543.003 Windows Service |
LoudMiner can automatically launch a Linux virtual machine as a service at startup if the AutoStart option is enabled in the VBoxVmService configuration file. |
| T1543.004 Launch Daemon |
LoudMiner adds plist files with the naming format |
| T1564.001 Hidden Files and Directories |
LoudMiner has set the attributes of the VirtualBox directory and VBoxVmService parent directory to "hidden". |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.