A North Korean Monero Cryptocurrency Miner

2018-01-08 Alienvault

https://www.alienvault.com/blogs/labs-research/a-north-korean-monero-cryptocurrency-miner

AlienVault analyzed a Christmas Eve 2017 Windows installer that deployed software likely to be xmrig for Monero mining. The installer copied intelservice.exe and updater.exe into C:\Windows\Sys64, launched a randomly named executable from C:\SoftwaresInstall, and passed mining arguments containing the wallet address 4JUdGzvrMFDWrUUwY3toJATSeNwjn54LkCnKBPRzDuhzi5vSepHfUckJNxRL2gjkNrSqtCoRUrEDAgRwsQvVCjZbRy5YeFCqgoUMnzumvS. Its configured mining server, barjuok.ryongnamsan.edu.kp, resolved to a Kim Il Sung University domain, but AlienVault noted that the hostname no longer resolved and did not attribute the installer to Lazarus. The report places the sample in the broader context of North Korean cryptocurrency interest and prior reporting on Bluenoroff and Andariel Monero mining, while emphasizing that this installer’s amateur Visual Basic implementation makes a Lazarus link unlikely.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN ryongnamsan.edu 2018-01-08 2026-01-27
DOMAIN barjuok.ryongnamsan.edu 2018-01-08 2018-01-09
YARA nkminer_monero 2018-01-08 2018-01-08
HASH 6a261443299788af1467142d5f538b2c 2018-01-08 2018-01-08
HASH 762c3249904a8bf76802effb54426655 2018-01-08 2018-01-08
HASH 42344bb45f351757e8638656e12a0135 2018-01-08 2018-01-08
IPv4 175.45.178.19 2017-05-30 2018-01-08

Related Reports

« Back