🚨Cryptomining campaigns continue to evolve beyond simple resource theft.
In our latest research, Group-IB analysts uncovered a covert Linux-based XMRig operation that leveraged trusted third-party access to infiltrate victim environments before deploying a heavily modified cryptomining implant engineered for stealth, persistence, and defence evasion.
Key Highlights:
🔹 Abuse of Linux PAM (pam_rootok) to impersonate multiple low-privileged users and create a forensic smokescreen.
🔹 Active log suppression and the use of a /tmp/.lock mutex to ensure single-instance execution without crashing the host.
🔹 A self-unlinking XMRig implant that deletes itself from disk and continues running entirely from memory.
🔹 Process masquerading, hidden artifacts (T1564.013), and network User-Agent spoofing as Java/Agent to blend Stratum traffic with legitimate web flows.
🔹 Campaign tracking identifiers (My-V25-GEN-26) linking infections to the V25-GEN-26 operation.
Read the full technical analysis.
#DFIR #XMRig
Post #979
957

- 🔥 6
- ❤ 2
- 👍 1