Meta tags:
Headings (most frequently used words):
loudminer, techniques, used, references, enterprise, layer,
Text of the page (most frequently used words):
the (27), loudminer (24), #enterprise (19), and (12), att (11), all (11), system (10), used (8), software (7), virtual (7), machine (6), has (6), files (6), ics (5), mobile (5), none (5), service (5), version (5), command (5), with (5), windows (5), mitre (4), resources (4), techniques (4), services (4), launch (4), for (4), cti (3), data (3), defenses (3), core (3), vst (3), qemu (3), launchctl (3), 001 (3), discovery (3), information (3), virtualization (3), process (3), file (3), obfuscated (3), miner (3), 004 (3), run (3), linux (3), macos (3), shell (3), 2026 (2), corporation (2), are (2), use (2), domains (2), reference (2), campaigns (2), groups (2), components (2), analytics (2), detection (2), strategies (2), assets (2), mitigations (2), tactics (2), matrices (2), objects (2), may (2), 2020 (2), started (2), infected (2), execution (2), folder (2), using (2), uses (2), daemon (2), library (2), launchdaemons (2), script (2), configuration (2), mine (2), cryptocurrency (2), xmrig (2), hijacking (2), encrypted (2), various (2), scripts (2), virtualbox (2), which (2), updates (2), hide (2), artifacts (2), set (2), directory (2), vboxvmservice (2), hidden (2), bundled (2), pirated (2), copies (2), studio (2), technology (2), plist (2), create (2), modify (2), can (2), 003 (2), scripting (2), interpreter (2), s0451 (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, contact, reset, filters, sub, malik, 2019, june, cross, platform, mining, cracked, retrieved, references, cryptomining, 002, launched, also, unload, when, updating, newer, t1569, gather, address, before, sending, network, t1016, monitored, cpu, usage, t1082, msi, installer, install, msiexec, binary, proxy, 007, t1218, harvested, monero, compute, resource, t1496, monitor, running, processes, t1057, dmg, encoded, 013, obfuscation, 010, t1027, scp, update, from, ingress, tool, transfer, t1105, deleted, installation, after, completion, deletion, indicator, removal, t1070, tiny, runs, makes, connections, server, instance, 006, attributes, parent, directories, t1564, typically, drive, compromise, t1189, adds, naming, format, runatload, keepalive, keys, true, com, random_name, automatically, startup, autostart, option, enabled, t1543, start, stop, unix, batch, t1059, name, domain, view, download, layer, navigator, layers, live, permalink, april, 2024, last, modified, created, platforms, malware, type, siphon, been, home, open, join, october, mclean, hotel, location, details, found, register, here, search, blog, contribute, benefactors, legal, branding, history, engage, tools, advisory, council, learn, more, about, get, detections,
Text of the page (random words):
loudminer software s0451 mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home software loudminer loudminer loudminer is a cryptocurrency miner which uses virtualization software to siphon system resources the miner has been bundled with pirated copies of virtual studio technology vst for windows and macos 1 id s0451 ⓘ type malware ⓘ platforms macos windows version 1 4 created 18 may 2020 last modified 11 april 2024 version permalink live version att ck navigator layers enterprise layer download view techniques used domain id name use enterprise t1059 003 command and scripting interpreter windows command shell loudminer used a batch script to run the linux virtual machine as a service 1 004 command and scripting interpreter unix shell loudminer used shell scripts to launch various services and to start stop the qemu virtualization 1 enterprise t1543 003 create or modify system process windows service loudminer can automatically launch a linux virtual machine as a service at startup if the autostart option is enabled in the vboxvmservice configuration file 1 004 create or modify system process launch daemon loudminer adds plist files with the naming format com random_name plist in the library launchdaemons folder with the runatload and keepalive keys set to true 1 enterprise t1189 drive by compromise loudminer is typically bundled with pirated copies of virtual studio technology vst for windows and macos 1 enterprise t1564 001 hide artifacts hidden files and directories loudminer has set the attributes of the virtualbox directory and vboxvmservice parent directory to hidden 1 006 hide artifacts run virtual instance loudminer has used qemu and virtualbox to run a tiny core linux virtual machine which runs xmrig and makes connections to the c2 server for updates 1 enterprise t1070 004 indicator removal file deletion loudminer deleted installation files after completion 1 enterprise t1105 ingress tool transfer loudminer used scp to update the miner from the c2 1 enterprise t1027 010 obfuscated files or information command obfuscation loudminer has obfuscated various scripts 1 013 obfuscated files or information encrypted encoded file loudminer has encrypted dmg files 1 enterprise t1057 process discovery loudminer used the ps command to monitor the running processes on the system 1 enterprise t1496 001 resource hijacking compute hijacking loudminer harvested system resources to mine cryptocurrency using xmrig to mine monero 1 enterprise t1218 007 system binary proxy execution msiexec loudminer used an msi installer to install the virtualization software 1 enterprise t1082 system information discovery loudminer has monitored cpu usage 1 enterprise t1016 system network configuration discovery loudminer used a script to gather the ip address of the infected machine before sending to the c2 1 enterprise t1569 001 system services launchctl loudminer launched the qemu services in the library launchdaemons folder using launchctl it also uses launchctl to unload all launch daemon s when updating to a newer version of loudminer 1 002 system services service execution loudminer started the cryptomining virtual machine as a service on the infected machine 1 references malik m 2019 june 20 loudminer cross platform mining in cracked vst software retrieved may 18 2020 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
|