NEW: Group Profiler — instant APT intel lookup. Try it →

Blue Mockingbird

Overview

Blue Mockingbird is a cluster of observed activity involving Monero cryptocurrency-mining payloads in dynamic-link library (DLL) form on Windows systems. The earliest observed Blue Mockingbird tools were created in December 2019.

Naming & attribution

Blue Mockingbird is tracked under 1 names across the industry. It uses 22 documented ATT&CK techniques — more than 55% of the 174 groups tracked here.

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1574.012 COR_PROFILER — used by 1 of 174 groups
  • T1134 Access Token Manipulation — used by 3 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Aquatic Panda China — 12 shared techniques (27% overlap)
  • Cinnamon Tempest China — 8 shared techniques (24% overlap)
  • FIN8 — 11 shared techniques (23% overlap)
  • APT19 China — 8 shared techniques (23% overlap)
  • Silence — 9 shared techniques (22% overlap)
  • APT41 China — 17 shared techniques (20% overlap)

Malware families with current indicators

One family attributed to Blue Mockingbird, carrying 1 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.

  • Frp 1 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1190

TTPs — 22 techniques across 12 tactics

Resource Development

Initial Access

Persistence

Defense Impairment

Credential Access

Lateral Movement

Command and Control

Impact

Tools & malware (2)

FRP · Mimikatz

Reporting (1)