A North Korean Monero Cryptocurrency Miner

2018-01-08 • Alienvault •

https://www.alienvault.com/blogs/labs-research/a-north-korean-monero-cryptocurrency-miner

AlienVault analyzed a Christmas Eve 2017 Windows installer that deployed software likely to be xmrig for Monero mining. The installer copied intelservice.exe and updater.exe into C:\Windows\Sys64, launched a randomly named executable from C:\SoftwaresInstall, and passed mining arguments containing the wallet address 4JUdGzvrMFDWrUUwY3toJATSeNwjn54LkCnKBPRzDuhzi5vSepHfUckJNxRL2gjkNrSqtCoRUrEDAgRwsQvVCjZbRy5YeFCqgoUMnzumvS. Its configured mining server, barjuok.ryongnamsan.edu.kp, resolved to a Kim Il Sung University domain, but AlienVault noted that the hostname no longer resolved and did not attribute the installer to Lazarus. The report places the sample in the broader context of North Korean cryptocurrency interest and prior reporting on Bluenoroff and Andariel Monero mining, while emphasizing that this installer’s amateur Visual Basic implementation makes a Lazarus link unlikely.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN ryongnamsan.edu 2018-01-08 2026-01-27
HASH c599f3ca3417169e4a620b8231f8a97… 2018-01-08 2018-01-09
HASH 42300b6a09f183ae167d7a11d9c6df2… 2018-01-08 2018-01-09
HASH 0024e32c0199ded445c0b968601f21c… 2018-01-08 2018-01-09
DOMAIN barjuok.ryongnamsan.edu 2018-01-08 2018-01-09
YARA nkminer_monero 2018-01-08 2018-01-08
IPv4 175.45.178.19 2017-05-30 2018-01-08

Related Reports

« Back