Returned Libra

Aliases: 8220 Mining Group

First seen
2017-01-01 00:00:00
Primary motivation
financial-gain
Sophistication
intermediate
Resource level
team
Actor type
criminal
Profile updated
2026-07-07 12:02:49

Targeted industries: technology-and-telecommunications

Context

Returned Libra, also known as 8220 Mining Group, is a cloud threat actor group that has been active since at least 2017. Tools commonly employed during their operations are PwnRig or DBUsed which are customized variants of the XMRig Monero mining software. The Returned Libra mining group is believed to have originated from a GitHub fork of the Rocke group's software. Returned Libra has elevated its mining operations with the use of cloud service platform credential scrapping.

Reports & references

  • Palo Alto Unit 42 — Returnedlibra (report)

External references