VictoryGate

First seen
2019-05-01 00:00:00
Malware type
cryptominer, botnet
Family
Malware family
Profile updated
2026-07-07 14:04:38

Targeted industries: government-and-public-sector

Targeted regions: country_code:pe

Context

VictoryGate was the name of a cryptomining botnet, which was disrupted by ESET researchers in April 2020. The used malware itself was also referred to as VictoryGate. It was spotted in May 2019 and targeted mainly Latin American users, specifically, Peru (Criptonizando states 90% of the botnet publication residing there). Both public and private sectors were targeted. This cryptojacking malware was specialized in Monero (XRM) cryptocurrency. VictoryGate shows very strong code overlap with win.orchard.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Victorygate_Auto (yara-rule)

Reports & references

  • advintel.io — Economic Growth Digital Inclusion Specialized Crime Financial Cyber Fraud In Latam (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Victorygate (report)
  • eset.com — Eset Researchers Disrupt Cryptomining Botnet Victorygate (report)
  • ESET — Eset Discovery Monero Mining Botnet Disrupted (report)
  • criptonizando.com — 35 Mil Computadores Foram Infectados Na America Latina Por Malware Que Minerava Monero (report)

External references