← Back to Actors
Blue Mockingbird
Blue Mockingbird
[Blue Mockingbird](https://attack.mitre.org/groups/G0108) is a cluster of observed activity involving Monero cryptocurrency-mining payloads in dynamic-link library (DLL) form on Windows systems. The earliest observed Blue Mockingbird tools were created in December 2019.(Citation: RedCanary Mockingbird May 2020)
22
Techniques
22
Covered
0
Gaps
100%
Coverage
Coverage22/22
COVERED (22)
T1003.001LSASS Memory105 det.T1021.001Remote Desktop Protocol51 det.T1021.002SMB/Windows Admin Shares67 det.T1027.013Encrypted/Encoded File7 det.T1036.005Match Legitimate Resource Name or Location44 det.T1047Windows Management Instrumentation85 det.T1053.005Scheduled Task82 det.T1059.001PowerShell338 det.T1059.003Windows Command Shell79 det.T1082System Information Discovery80 det.T1090Proxy44 det.T1112Modify Registry197 det.T1134Access Token Manipulation24 det.T1190Exploit Public-Facing Application208 det.T1218.010Regsvr3241 det.T1218.011Rundll3273 det.T1496.001Compute Hijacking2 det.T1543.003Windows Service79 det.T1546.003Windows Management Instrumentation Event Subscription17 det.T1569.002Service Execution63 det.T1574.012COR_PROFILER2 det.T1588.002Tool13 det.