🌐Blue Mockingbird
🌐 Blue Mockingbird is a tracked threat actor in the Clankerusecase corpus. ??-aligned. Primary motivation: Unknown. We map 14 detection use cases to this actor across 22 MITRE ATT&CK techniques, with 0 threat-intel articles citing them.
14Use cases
0Articles
22Techniques
0IOCs
About this actor (MITRE)
[Blue Mockingbird](https://attack.mitre.org/groups/G0108) is a cluster of observed activity involving Monero cryptocurrency-mining payloads in dynamic-link library (DLL) form on Windows systems. The earliest observed Blue Mockingbird tools were created in December 2019.(Citation: RedCanary Mockingbird May 2020)
Known aliases
Blue Mockingbird
Top techniques
All other tracked techniques
T1027.013 · Encrypted/Encoded FileT1036.005 · Match Legitimate Resource Name or LocationT1047 · Windows Management InstrumentationT1053.005 · Scheduled TaskT1059.001 · PowerShellT1059.003 · Windows Command ShellT1082 · System Information DiscoveryT1090 · ProxyT1112 · Modify RegistryT1134 · Access Token ManipulationT1190 · Exploit Public-Facing ApplicationT1218.010 · Regsvr32T1218.011 · Rundll32T1496.001 · Compute HijackingT1543.003 · Windows ServiceT1546.003 · Windows Management Instrumentation Event SubscriptionT1569.002 · Service ExecutionT1574.012 · COR_PROFILERT1588.002 · Tool