Blue Mockingbird
Blue Mockingbird is a cluster of observed activity involving Monero cryptocurrency-mining payloads in dynamic-link library (DLL) form on Windows systems. The earliest observed Blue Mockingbird tools were created in December 2019.
Blue Mockingbird is an activity cluster deploying Monero cryptocurrency miners on public-facing Windows servers.
Blue Mockingbird is an activity cluster leveraging Monero cryptocurrency-mining DLL payloads on Windows systems. They target servers with public-facing applications, gaining initial access via exploit. Core TTPs include PowerShell, WMI Event Subscriptions for persistence and privilege escalation, COR_PROFILER DLL hijacking, LSASS memory credential dumping with Mimikatz, and lateral movement via RDP and SMB. Defenders should monitor for suspicious PowerShell execution, unusual Scheduled Tasks and Windows Services, registry modifications, and high CPU usage indicative of cryptomining.
Blue Mockingbird is a cluster of observed activity involving Monero cryptocurrency-mining payloads in dynamic-link library (DLL) form on Windows systems. The earliest observed Blue Mockingbird tools were created in December 2019.
Monitor suspicious downloads and open-source intelligence to obtain tools.
Analyze web proxy logs to detect exploit attempts on public-facing applications.
Monitor system logs to detect suspicious PowerShell execution and scheduled task creations.
Monitor system configuration changes to detect new Windows service creations.
Monitor WMI activity to detect suspicious Windows Management Instrumentation (WMI) event subscriptions.
Monitor process execution to detect suspicious Rundll32 and COR_PROFILER usage.
Monitor credential access attempts to detect attempts to obtain credentials from LSASS memory.
Monitor system queries to detect system information discovery attempts.
Monitor network traffic to detect suspicious RDP and SMB connections.
Analyze network traffic to detect suspicious proxy usage.
Monitor registry changes to detect suspicious registry modifications.
Monitor system performance to detect suspicious compute resource usage.
Blue Mockingbird primarily targets servers with public-facing applications.
Blue Mockingbird performs DLL hijacking via COR_PROFILER.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.