A North Korean Monero Cryptocurrency Miner
2018-01-08 • Alienvault •
https://www.alienvault.com/blogs/labs-research/a-north-korean-monero-cryptocurrency-miner
AlienVault analyzed a Christmas Eve 2017 Windows installer that deployed software likely to be xmrig for Monero mining. The installer copied intelservice.exe and updater.exe into C:\Windows\Sys64, launched a randomly named executable from C:\SoftwaresInstall, and passed mining arguments containing the wallet address 4JUdGzvrMFDWrUUwY3toJATSeNwjn54LkCnKBPRzDuhzi5vSepHfUckJNxRL2gjkNrSqtCoRUrEDAgRwsQvVCjZbRy5YeFCqgoUMnzumvS. Its configured mining server, barjuok.ryongnamsan.edu.kp, resolved to a Kim Il Sung University domain, but AlienVault noted that the hostname no longer resolved and did not attribute the installer to Lazarus. The report places the sample in the broader context of North Korean cryptocurrency interest and prior reporting on Bluenoroff and Andariel Monero mining, while emphasizing that this installer’s amateur Visual Basic implementation makes a Lazarus link unlikely.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | ryongnamsan.edu | 2018-01-08 | 2026-01-27 |
| DOMAIN | barjuok.ryongnamsan.edu | 2018-01-08 | 2018-01-09 |
| YARA | nkminer_monero | 2018-01-08 | 2018-01-08 |
| HASH | 6a261443299788af1467142d5f538b2c | 2018-01-08 | 2018-01-08 |
| HASH | 762c3249904a8bf76802effb54426655 | 2018-01-08 | 2018-01-08 |
| HASH | 42344bb45f351757e8638656e12a0135 | 2018-01-08 | 2018-01-08 |
| IPv4 | 175.45.178.19 | 2017-05-30 | 2018-01-08 |