coinminer_dropper_attacker is an uncategorized intrusion actor label used for attackers observed exploiting Microsoft Exchange Server vulnerabilities disclosed in 2021 to gain remote code execution and elevated access on exposed servers, then using PowerShell to retrieve and execute cryptocurrency-mining payloads. The activity fits opportunistic post-exploitation following mass exploitation of Exchange flaws rather than a well-attributed, distinct intrusion set. Observed tradecraft associated with this activity includes exploitation of public-facing applications for initial access, deployment of webshells, use of command interpreters and PowerShell, reconnaissance of hosts and Active Directory environments, credential dumping, ingress tool transfer, use of legitimate administrative utilities, and defense evasion through file hiding and log clearing. The broader intrusion clusters active in the same exploitation wave also used remote access tooling, data exfiltration, and other second-stage payloads, but only the coinminer-delivery behavior is specifically attributable to this label. Attribution to a nation state or a specific criminal group is not supported at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.