Pacha Group is a cryptojacking threat actor known for Linux-focused cryptocurrency mining activity. It has been referenced in connection with XMRig-based mining operations and has been observed in competitive overlap with other Linux and cloud cryptomining actors, including Rocke Group, with reporting noting a partial code-base overlap between tooling associated with the two groups and subsequent competition for cryptomining footholds on Linux-based cloud servers. Publicly available information in this context is limited, and high-confidence details about its organizational structure, sponsorship, sub-groups, or broader intrusion lifecycle are not established. Based on confirmed reporting, the group is associated with unauthorized Monero mining on compromised infrastructure rather than ransomware or espionage operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as another threat actor observed using XMRig.
Referenced as a competing cryptomining threat actor group in the same Linux cloud server ecosystem.
Mentioned as a background cryptojacking group whose tools/code overlapped with other groups and which was involved in a crypto war with Rocke.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.