Blue Mockingbird
MITRE ATT&CK: G0108 View on attack.mitre.org
Aliases: Blue Mockingbird
- First seen
- 2019-12-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- intermediate
- Resource level
- team
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:30:17
Targeted industries: technology-and-telecommunications financial-services government-and-public-sector
Context
Blue Mockingbird is a cluster of observed activity involving Monero cryptocurrency-mining payloads in dynamic-link library (DLL) form on Windows systems. The earliest observed Blue Mockingbird tools were created in December 2019.
Detection coverage
- 7 YARA rules
- 743 Sigma rules
Malware & tools used
- PowerShell (attack-pattern)
- COR_PROFILER (attack-pattern)
- Windows Management Instrumentation Event Subscription (attack-pattern)
- System Information Discovery (attack-pattern)
- Windows Service (attack-pattern)
- Scheduled Task (attack-pattern)
- Proxy (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Windows Command Shell (attack-pattern)
- LSASS Memory (attack-pattern)
- Rundll32 (attack-pattern)
- Access Token Manipulation (attack-pattern)
- Compute Hijacking (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Modify Registry (attack-pattern)
- Service Execution (attack-pattern)
- Exploit Public-Facing Application (attack-pattern)
- Remote Desktop Protocol (attack-pattern)
- Regsvr32 (attack-pattern)
- SMB/Windows Admin Shares (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Tool (attack-pattern)
- FRP (malware)
- Mimikatz (malware)
Reports & references
- MITRE ATT&CK — G0108 (report)
- redcanary.com — Blue Mockingbird Cryptominer (report)