← Back to Actors
Blue Mockingbird
Blue Mockingbird
[Blue Mockingbird](https://attack.mitre.org/groups/G0108) is a cluster of observed activity involving Monero cryptocurrency-mining payloads in dynamic-link library (DLL) form on Windows systems. The earliest observed Blue Mockingbird tools were created in December 2019.(Citation: RedCanary Mockingbird May 2020)
22
Techniques
22
Covered
0
Gaps
100%
Coverage
Coverage22/22
COVERED (22)
T1003.001LSASS Memory111 det.T1021.001Remote Desktop Protocol54 det.T1021.002SMB/Windows Admin Shares74 det.T1027.013Encrypted/Encoded File8 det.T1036.005Match Legitimate Resource Name or Location45 det.T1047Windows Management Instrumentation88 det.T1053.005Scheduled Task100 det.T1059.001PowerShell376 det.T1059.003Windows Command Shell87 det.T1082System Information Discovery88 det.T1090Proxy49 det.T1112Modify Registry205 det.T1134Access Token Manipulation31 det.T1190Exploit Public-Facing Application233 det.T1218.010Regsvr3243 det.T1218.011Rundll3276 det.T1496.001Compute Hijacking2 det.T1543.003Windows Service80 det.T1546.003Windows Management Instrumentation Event Subscription18 det.T1569.002Service Execution65 det.T1574.012COR_PROFILER2 det.T1588.002Tool13 det.