G0108: Blue Mockingbird
Blue Mockingbird is a cluster of observed activity involving Monero cryptocurrency-mining payloads in dynamic-link library (DLL) form on Windows systems. The earliest observed Blue Mockingbird tools were created in December 2019.[1]
Security context for executives and security teams
G0108: Blue Mockingbird describes [Blue Mockingbird](https://attack.mitre.org/groups/G0108) is a cluster of observed activity involving Monero cryptocurrency-mining payloads in dynamic-link library (DLL) form on Windows systems. The earliest observed Blue Mockingbird tools were created in December 2019.(Citation: RedCanary Mockingbird May 2020)
Executive priority
G0108: Blue Mockingbird is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate G0108: Blue Mockingbird by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
Detection direction
- Validate whether G0108: Blue Mockingbird appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Blue Mockingbird
Blue Mockingbird is a cluster of observed activity involving Monero cryptocurrency-mining payloads in dynamic-link library (DLL) form on Windows systems. The earliest observed Blue Mockingbird tools were created in December 2019.[1]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1059.001 | PowerShellSub-technique | Blue Mockingbird has used PowerShell reverse TCP shells to issue interactive commands over a network connection.[1] |
| Enterprise | T1574.012 | COR_PROFILERSub-technique | Blue Mockingbird has used wmic.exe and Windows Registry modifications to set the COR_PROFILER environment variable to execute a malicious DLL whenever a process loads the .NET CLR.[1] |
| Enterprise | T1546.003 | Windows Management Instrumentation Event SubscriptionSub-technique | Blue Mockingbird has used mofcomp.exe to establish WMI Event Subscription persistence mechanisms configured from a *.mof file.[1] |
| Enterprise | T1082 | System Information Discovery | Blue Mockingbird has collected hardware details for the victim's system, including CPU and memory information.[1] |
| Enterprise | T1543.003 | Windows ServiceSub-technique | Blue Mockingbird has made their XMRIG payloads persistent as a Windows Service.[1] |
| Enterprise | T1053.005 | Scheduled TaskSub-technique | Blue Mockingbird has used Windows Scheduled Tasks to establish persistence on local and remote hosts.[1] |
| Enterprise | T1090 | Proxy | Blue Mockingbird has used FRP, ssf, and Venom to establish SOCKS proxy connections.[1] |
| Enterprise | T1047 | Windows Management Instrumentation | Blue Mockingbird has used wmic.exe to set environment variables.[1] |
| Enterprise | T1059.003 | Windows Command ShellSub-technique | Blue Mockingbird has used batch script files to automate execution and deployment of payloads.[1] |
| Enterprise | T1003.001 | LSASS MemorySub-technique | Blue Mockingbird has used Mimikatz to retrieve credentials from LSASS memory.[1] |
| Enterprise | T1218.011 | Rundll32Sub-technique | Blue Mockingbird has executed custom-compiled XMRIG miner DLLs using rundll32.exe.[1] |
| Enterprise | T1134 | Access Token Manipulation | Blue Mockingbird has used JuicyPotato to abuse the |
| Enterprise | T1496.001 | Compute HijackingSub-technique | Blue Mockingbird has used XMRIG to mine cryptocurrency on victim systems.[1] |
| Enterprise | T1027.013 | Encrypted/Encoded FileSub-technique | Blue Mockingbird has obfuscated the wallet address in the payload binary.[1] |
| Enterprise | T1112 | Modify Registry | Blue Mockingbird has used Windows Registry modifications to specify a DLL payload.[1] |
| Enterprise | T1569.002 | Service ExecutionSub-technique | Blue Mockingbird has executed custom-compiled XMRIG miner DLLs by configuring them to execute via the "wercplsupport" service.[1] |
| Enterprise | T1190 | Exploit Public-Facing Application | Blue Mockingbird has gained initial access by exploiting CVE-2019-18935, a vulnerability within Telerik UI for ASP.NET AJAX.[1] |
| Enterprise | T1021.001 | Remote Desktop ProtocolSub-technique | Blue Mockingbird has used Remote Desktop to log on to servers interactively and manually copy files to remote hosts.[1] |
| Enterprise | T1218.010 | Regsvr32Sub-technique | Blue Mockingbird has executed custom-compiled XMRIG miner DLLs using regsvr32.exe.[1] |
| Enterprise | T1021.002 | SMB/Windows Admin SharesSub-technique | Blue Mockingbird has used Windows Explorer to manually copy malicious files to remote hosts over SMB.[1] |
| Enterprise | T1036.005 | Match Legitimate Resource Name or LocationSub-technique | Blue Mockingbird has masqueraded their XMRIG payload name by naming it wercplsupporte.dll after the legitimate wercplsupport.dll file.[1] |
| Enterprise | T1588.002 | ToolSub-technique | Blue Mockingbird has obtained and used tools such as Mimikatz.[1] |
Groups, software, and campaigns
S1144: FRP
FRP, which stands for Fast Reverse Proxy, is an openly available tool that is capable of exposing a server located behind a firewall or Network Address Translation (NAT) to the Internet. FRP can support multiple protocols including TCP, UDP, and HTTP(S) and has been abused by threat actors to proxy command and control communications.[1][2][3][4]
S0002: Mimikatz
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 1.3 | Current bundle | 58e2cf936fb1… | ||
| 19.1 | 1.3 | Older bundle | 3751d2a13f33… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]RedCanary Mockingbird May 2020
Lambert, T. (2020, May 7). Introducing Blue Mockingbird. Retrieved May 26, 2020.
Open source URL - [2]mitre-attackG0108Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
