LoudMiner

S0451

Malware.View on attack.mitre.org

About this malware

LoudMiner is a cryptocurrency miner which uses virtualization software to siphon system resources. The miner has been bundled with pirated copies of Virtual Studio Technology (VST) for Windows and macOS.

Techniques used18

Procedure examples18

TechniqueProcedure example
T1016
System Network Configuration Discovery

LoudMiner used a script to gather the IP address of the infected machine before sending to the C2.

T1027.010
Command Obfuscation

LoudMiner has obfuscated various scripts.

T1027.013
Encrypted/Encoded File

LoudMiner has encrypted DMG files.

T1057
Process Discovery

LoudMiner used the ps command to monitor the running processes on the system.

T1059.003
Windows Command Shell

LoudMiner used a batch script to run the Linux virtual machine as a service.

T1059.004
Unix Shell

LoudMiner used shell scripts to launch various services and to start/stop the QEMU virtualization.

T1070.004
File Deletion

LoudMiner deleted installation files after completion.

T1082
System Information Discovery

LoudMiner has monitored CPU usage.

T1105
Ingress Tool Transfer

LoudMiner used SCP to update the miner from the C2.

T1189
Drive-by Compromise

LoudMiner is typically bundled with pirated copies of Virtual Studio Technology (VST) for Windows and macOS.

T1218.007
Msiexec

LoudMiner used an MSI installer to install the virtualization software.

T1496.001
Compute Hijacking

LoudMiner harvested system resources to mine cryptocurrency, using XMRig to mine Monero.

T1543.003
Windows Service

LoudMiner can automatically launch a Linux virtual machine as a service at startup if the AutoStart option is enabled in the VBoxVmService configuration file.

T1543.004
Launch Daemon

LoudMiner adds plist files with the naming format com.[random_name].plist in the /Library/LaunchDaemons folder with the RunAtLoad and KeepAlive keys set to true.

T1564.001
Hidden Files and Directories

LoudMiner has set the attributes of the VirtualBox directory and VBoxVmService parent directory to "hidden".

View all 18 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. ESET LoudMiner June 2019 Open source
    Malik, M. (2019, June 20). LoudMiner: Cross-platform mining in cracked VST software. Retrieved May 18, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.