Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
22
techniques
2
software
10,727
corpus matches
profile
Blue Mockingbird is a cluster of observed activity involving Monero cryptocurrency-mining payloads in dynamic-link library (DLL) form on Windows systems. The earliest observed Blue Mockingbird tools were created in December 2019.
techniques
22 attributed · most-instrumented first
PowerShell
execution
Tool
resource-development
Windows Command Shell
execution
Match Legitimate Resource Name or Location
stealth
System Information Discovery
discovery
Scheduled Task
+10 more techniques
software
2 malware & tools attributed
Mimikatz
S0002
FRP
S1144
read this carefully
10,727 corpus matches is not attribution
That count is indicators which exhibit techniques Blue Mockingbird is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
execution · persistence · privilege-escalation
showing 30 of 10,727