TGViewer
Group-IB Group-IB @group_ib · 2.52K subscribers
Post #979 957
🚨Cryptomining campaigns continue to evolve beyond simple resource theft.

In our latest research, Group-IB analysts uncovered a covert Linux-based XMRig operation that leveraged trusted third-party access to infiltrate victim environments before deploying a heavily modified cryptomining implant engineered for stealth, persistence, and defence evasion.

Key Highlights:
🔹 Abuse of Linux PAM (pam_rootok) to impersonate multiple low-privileged users and create a forensic smokescreen.
🔹 Active log suppression and the use of a /tmp/.lock mutex to ensure single-instance execution without crashing the host.
🔹 A self-unlinking XMRig implant that deletes itself from disk and continues running entirely from memory.
🔹 Process masquerading, hidden artifacts (T1564.013), and network User-Agent spoofing as Java/Agent to blend Stratum traffic with legitimate web flows.
🔹 Campaign tracking identifiers (My-V25-GEN-26) linking infections to the V25-GEN-26 operation.

Read the full technical analysis.

#DFIR #XMRig
  • 🔥 6
  • ❤ 2
  • 👍 1
More from @group_ib
  1. Sep 23, 2026🚨Group-IB researchers have uncovered RemControl, a previously undocumented Android bankin…
  2. Sep 17, 2026🚨Group-IB Threat Intelligence has uncovered 29 new samples linked to the HEAVYGRAM and CR…
  3. Sep 14, 2026🚨 Inside the Smishing Triad’s Phishing Cockpit Group-IB’s latest research dives into JWR,…
  4. Sep 9, 2026🚨 Group-IB uncovers Vwork, a weaponized fork of the open-source Android app cloner Shelte…
  5. Sep 3, 2026🚨 Outsider Phishing Kit: a resilient PhaaS threat Group-IB researchers uncovered the Outs…
  6. Sep 1, 2026🚨 Cybercrime is evolving, and so is the underground economy behind it. Group-IB has uncov…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →