VictoryGate
- First seen
- 2019-05-01 00:00:00
- Malware type
- cryptominer, botnet
- Family
- Malware family
- Profile updated
- 2026-07-07 14:04:38
Targeted industries: government-and-public-sector
Targeted regions: country_code:pe
Context
VictoryGate was the name of a cryptomining botnet, which was disrupted by ESET researchers in April 2020. The used malware itself was also referred to as VictoryGate. It was spotted in May 2019 and targeted mainly Latin American users, specifically, Peru (Criptonizando states 90% of the botnet publication residing there). Both public and private sectors were targeted. This cryptojacking malware was specialized in Monero (XRM) cryptocurrency. VictoryGate shows very strong code overlap with win.orchard.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Victorygate_Auto (yara-rule)
Reports & references
- advintel.io — Economic Growth Digital Inclusion Specialized Crime Financial Cyber Fraud In Latam (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Victorygate (report)
- eset.com — Eset Researchers Disrupt Cryptomining Botnet Victorygate (report)
- ESET — Eset Discovery Monero Mining Botnet Disrupted (report)
- criptonizando.com — 35 Mil Computadores Foram Infectados Na America Latina Por Malware Que Minerava Monero (report)