ATT&CKGroupsBlue Mockingbird

Blue Mockingbird

G0108

Threat group.View on attack.mitre.org

About this group

Blue Mockingbird is a cluster of observed activity involving Monero cryptocurrency-mining payloads in dynamic-link library (DLL) form on Windows systems. The earliest observed Blue Mockingbird tools were created in December 2019.

Techniques used22

Procedure examples22

TechniqueProcedure example
T1003.001
LSASS Memory

Blue Mockingbird has used Mimikatz to retrieve credentials from LSASS memory.

T1021.001
Remote Desktop Protocol

Blue Mockingbird has used Remote Desktop to log on to servers interactively and manually copy files to remote hosts.

T1021.002
SMB/Windows Admin Shares

Blue Mockingbird has used Windows Explorer to manually copy malicious files to remote hosts over SMB.

T1027.013
Encrypted/Encoded File

Blue Mockingbird has obfuscated the wallet address in the payload binary.

T1036.005
Match Legitimate Resource Name or Location

Blue Mockingbird has masqueraded their XMRIG payload name by naming it wercplsupporte.dll after the legitimate wercplsupport.dll file.

T1047
Windows Management Instrumentation

Blue Mockingbird has used wmic.exe to set environment variables.

T1053.005
Scheduled Task

Blue Mockingbird has used Windows Scheduled Tasks to establish persistence on local and remote hosts.

T1059.001
PowerShell

Blue Mockingbird has used PowerShell reverse TCP shells to issue interactive commands over a network connection.

T1059.003
Windows Command Shell

Blue Mockingbird has used batch script files to automate execution and deployment of payloads.

T1082
System Information Discovery

Blue Mockingbird has collected hardware details for the victim's system, including CPU and memory information.

T1090
Proxy

Blue Mockingbird has used FRP, ssf, and Venom to establish SOCKS proxy connections.

T1112
Modify Registry

Blue Mockingbird has used Windows Registry modifications to specify a DLL payload.

T1134
Access Token Manipulation

Blue Mockingbird has used JuicyPotato to abuse the SeImpersonate token privilege to escalate from web application pool accounts to NT Authority\SYSTEM.

T1190
Exploit Public-Facing Application

Blue Mockingbird has gained initial access by exploiting CVE-2019-18935, a vulnerability within Telerik UI for ASP.NET AJAX.

T1218.010
Regsvr32

Blue Mockingbird has executed custom-compiled XMRIG miner DLLs using regsvr32.exe.

View all 22 procedure examples

Software2

Campaigns0

None recorded.

References1

  1. RedCanary Mockingbird May 2020 Open source
    Lambert, T. (2020, May 7). Introducing Blue Mockingbird. Retrieved May 26, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.