← Back to Actors
Blue Mockingbird
Blue Mockingbird
[Blue Mockingbird](https://attack.mitre.org/groups/G0108) is a cluster of observed activity involving Monero cryptocurrency-mining payloads in dynamic-link library (DLL) form on Windows systems. The earliest observed Blue Mockingbird tools were created in December 2019.(Citation: RedCanary Mockingbird May 2020)
22
Techniques
22
Covered
0
Gaps
100%
Coverage
Coverage22/22
COVERED (22)
T1003.001LSASS Memory111 det.T1021.001Remote Desktop Protocol53 det.T1021.002SMB/Windows Admin Shares73 det.T1027.013Encrypted/Encoded File8 det.T1036.005Match Legitimate Resource Name or Location44 det.T1047Windows Management Instrumentation87 det.T1053.005Scheduled Task99 det.T1059.001PowerShell368 det.T1059.003Windows Command Shell82 det.T1082System Information Discovery86 det.T1090Proxy46 det.T1112Modify Registry203 det.T1134Access Token Manipulation28 det.T1190Exploit Public-Facing Application216 det.T1218.010Regsvr3243 det.T1218.011Rundll3275 det.T1496.001Compute Hijacking2 det.T1543.003Windows Service79 det.T1546.003Windows Management Instrumentation Event Subscription18 det.T1569.002Service Execution64 det.T1574.012COR_PROFILER2 det.T1588.002Tool13 det.