Lucifer

MITRE ATT&CK: S0532 View on attack.mitre.org

Aliases: Lucifer

First seen
2020-06-11 00:00:00
Malware type
cryptominer, ddos, worm
Family
Malware family
Operating systems
windows
Related IoCs
38 (31 malicious)
Last IoC activity
2026-08-22 00:21:47
Profile updated
2026-07-07 15:10:19

Targeted industries: technology-and-telecommunications energy-and-utilities financial-services

Context

Lucifer is a crypto miner and DDoS hybrid malware that leverages well-known exploits to spread laterally on Windows platforms.

Recent IoC activity

31 malicious indicators in Maltiverse are attributed to Lucifer (S0532). The 20 most recently updated:

Detection coverage

  • 1 YARA rules
  • 397 Sigma rules

Malware & tools used

  • Compute Hijacking (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Process Discovery (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Lateral Tool Transfer (attack-pattern)
  • System Checks (attack-pattern)
  • Software Packing (attack-pattern)
  • Scheduled Task (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Password Guessing (attack-pattern)
  • Network Denial of Service (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Application Layer Protocol (attack-pattern)
  • Exploitation of Remote Services (attack-pattern)
  • Clear Windows Event Logs (attack-pattern)
  • Network Service Discovery (attack-pattern)
  • SMB/Windows Admin Shares (attack-pattern)
  • Query Registry (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)

Detection rules

  • SEKOIA_Bot_Lin_Lucifer_Strings (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Lucifer (report)
  • research.checkpoint.com — Rudeminer Blacksquid And Lucifer Walk Into A Bar (report)
  • Palo Alto Unit 42 — Lucifer New Cryptojacking And Ddos Hybrid Malware (report)
  • MITRE ATT&CK — S0532 (report)

External references