Returned Libra is a cloud-focused threat actor known for hijacking resources for cryptocurrency mining.
Analyst brief
Returned Libra (8220 Mining Group) is a cloud-focused threat actor active since at least 2017, primarily targeting cloud service platforms. Their main TTPs involve credential scraping to hijack cloud resources and deploying custom XMRig variants like PwnRig or DBUsed for cryptomining. Defenders must focus on detecting unauthorized resource usage indicative of cryptomining and monitor for credential compromise across cloud platforms.
Returned Libra
8220 Mining Group
unknown
Returned Libra, also known as 8220 Mining Group, is a cloud threat actor group that has been active since at least 2017. Tools commonly employed during their operations are PwnRig or DBUsed which are customized variants of the XMRig Monero mining software. The Returned Libra mining group is believed to have originated from a GitHub fork of the Rocke group's software. Returned Libra has elevated its mining operations with the use of cloud service platform credential scrapping.