Moneybird

S1137

Malware.View on attack.mitre.org

About this malware

Moneybird is a ransomware variant written in C++ associated with Agrius operations. The name "Moneybird" is contained in the malware's ransom note and as strings in the executable.

Techniques used2

Procedure examples2

TechniqueProcedure example
T1027.009
Embedded Payloads

Moneybird contains a configuration blob embedded in the malware itself.

T1486
Data Encrypted for Impact

Moneybird targets a common set of file types such as documents, certificates, and database files for encryption while avoiding executable, dynamic linked libraries, and similar items.

Groups that use it1

Campaigns0

None recorded.

References1

  1. CheckPoint Agrius 2023 Open source
    Marc Salinas Fernandez & Jiri Vinopal. (2023, May 23). AGRIUS DEPLOYS MONEYBIRD IN TARGETED ATTACKS AGAINST ISRAELI ORGANIZATIONS. Retrieved May 21, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.