Blue Mockingbird
Overview
Blue Mockingbird is a cluster of observed activity involving Monero cryptocurrency-mining payloads in dynamic-link library (DLL) form on Windows systems. The earliest observed Blue Mockingbird tools were created in December 2019.
Naming & attribution
Blue Mockingbird is tracked under 1 names across the industry. It uses 22 documented ATT&CK techniques — more than 55% of the 174 groups tracked here.
Distinctive techniques
Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.
-
T1574.012COR_PROFILER — used by 1 of 174 groups -
T1134Access Token Manipulation — used by 3 of 174 groups
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- Aquatic Panda China — 12 shared techniques (27% overlap)
- Cinnamon Tempest China — 8 shared techniques (24% overlap)
- FIN8 — 11 shared techniques (23% overlap)
- APT19 China — 8 shared techniques (23% overlap)
- Silence — 9 shared techniques (22% overlap)
- APT41 China — 17 shared techniques (20% overlap)
Malware families with current indicators
One family attributed to Blue Mockingbird, carrying 1 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.
- Frp 1 indicators
Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.
Capabilities
- Exploitation of public-facing / client applications — ATT&CK T1190
TTPs — 22 techniques across 12 tactics
Resource Development
-
T1588.002Tool
Initial Access
Execution
-
T1047Windows Management Instrumentation -
T1053.005Scheduled Task -
T1059.001PowerShell -
T1059.003Windows Command Shell -
T1569.002Service Execution
Persistence
-
T1543.003Windows Service
Privilege Escalation
Stealth
-
T1027.013Encrypted/Encoded File -
T1036.005Match Legitimate Resource Name or Location -
T1134Access Token Manipulation -
T1218.010Regsvr32 -
T1218.011Rundll32 -
T1574.012COR_PROFILER
Defense Impairment
-
T1112Modify Registry
Credential Access
-
T1003.001LSASS Memory
Discovery
Lateral Movement
-
T1021.001Remote Desktop Protocol -
T1021.002SMB/Windows Admin Shares
Command and Control
-
T1090Proxy
Impact
-
T1496.001Compute Hijacking
Tools & malware (2)
FRP · Mimikatz
Reporting (1)
- Introducing Blue Mockingbird — Lambert, T