monib110 is a threat actor associated with a malicious RubyGems supply-chain campaign that distributed trojanized Ruby packages to covertly mine Monero on developer systems. The operation used packages that mimicked legitimate Ruby libraries, including typosquatted variants, to induce installation by developers using the public RubyGems ecosystem. Once installed, the malicious packages executed hidden Ruby code that retrieved and launched cryptocurrency-mining payloads. The monib110-associated activity is one of two related RubyGems clusters identified in the broader campaign. In this cluster, 23 malicious packages were uploaded. The actor’s tradecraft centered on initial access through package-repository abuse and software supply-chain compromise rather than direct exploitation of exposed services. The payloads were simpler than those used by the related cluster and did not exhibit the same level of persistence or anti-analysis behavior, but they still enabled unauthorized cryptomining on victim machines. Across the broader related campaign, malicious packages altered library entry points and, in more advanced variants, supported post-compromise propagation through developer environments. Observed behaviors included searching for SSH keys and known-host records, attempting access to trusted remote systems, and modifying development-related assets such as Node.js package files, Python setup scripts, Ruby gem specifications, Dockerfiles, Git hooks, and Visual Studio Code extensions to spread further. These behaviors indicate capability for lateral movement, credential theft via SSH key harvesting, post-exploitation, and exfiltration of authentication material, although the monib110-linked cluster is specifically characterized by direct miner delivery through hidden Ruby code. The actor’s activity primarily targeted software developers and development environments through public package repositories, making the information technology sector the clearest victim category. The dominant motivation is financial, as the operation’s objective was unauthorized Monero mining rather than espionage, disruption, or extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 malware family attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.