MyKings is a financially motivated cryptomining botnet and malware operation known for distributing cryptocurrency-mining payloads and related monetization malware. It has been associated with clipboard-stealer functionality and has been discussed alongside other resurgent miner-focused threats such as PowerGhost. MyKings has been used as a delivery mechanism for additional malware, including cases where a clipboard-stealer payload was one infection path for CoinHelper, although that delivery overlap is insufficient to attribute CoinHelper operations to the MyKings botnet itself. The actor’s activity is centered on illicit cryptocurrency mining and related post-compromise monetization. High-confidence reporting in the supplied material supports association with cryptomining operations and clipboard theft behavior, but does not provide sufficiently corroborated detail on MyKings’ full intrusion lifecycle, victimology, geographic origin, or specific sector targeting. Based on the available facts, MyKings should be characterized as a cybercriminal operation focused primarily on financial gain through cryptomining and theft of cryptocurrency transaction data via clipboard manipulation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a botnet whose clipboard stealer was used as one infection vector to spread CoinHelper, but the content explicitly says CoinHelper cannot be attributed to MyKings based on available evidence.
Mentioned only as another cryptomining threat seen resurging during the same period, not as part of the Tor2Mine activity itself.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.