MeatyBanana is a cybercriminal actor observed in 2017 advertising a Monero-mining utility for Windows systems. The offering went beyond simple cryptomining and included additional bot-like functionality, notably the ability to download and execute arbitrary payloads, launch distributed denial-of-service attacks, maintain persistence, and spread via removable media. The malware was also marketed with stealth features intended to evade user and administrator detection on infected hosts. The actor’s known activity is consistent with financially motivated criminal operations centered on illicit cryptocurrency mining, while retaining secondary capabilities that could support broader post-compromise abuse. Reported functionality included registry-based persistence, tasking support for remote actions, and propagation through USB devices. The combination of cryptomining, payload delivery, persistence, and DDoS capability indicates an opportunistic threat profile that blends monetization with flexible post-exploitation options. No high-confidence attribution to a nation state is established. Publicly available information directly ties MeatyBanana to the sale of a multifunctional miner rather than to a broader, well-documented intrusion set or formal subgroup structure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.