BOINC (Berkeley Open Infrastructure for Network Computing) is a legitimate open-source distributed computing platform that, in the provided reporting, appears as a modified malicious payload deployed by the MintsLoader malware loader. Multiple sources state that MintsLoader has delivered a modified BOINC client configured to connect to attacker-controlled or malicious infrastructure rather than standard BOINC project servers, enabling cryptomining or compute theft. This modified BOINC payload has been observed alongside other MintsLoader-delivered payloads such as GhostWeaver and StealC. The associated delivery activity is tied to MintsLoader campaigns attributed primarily to TAG-124/LandUpdate808, and also observed in SocGholish/FakeUpdates activity. Reported infection vectors for the broader delivery chain include phishing emails, fake browser update prompts on compromised websites, invoice-themed JavaScript lures including via Italy’s PEC email system, and ClickFix/KongTuke-style social engineering that tricks users into executing PowerShell or related commands. The broader campaigns targeted Windows endpoints, with targeting reported against industrial, legal, energy, oil and gas, and related sectors in the United States and Europe. High-confidence behavior directly stated in the content is limited to the BOINC client being modified and redirected to attacker-controlled project servers/C2 for unauthorized resource use.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Modified BOINC client repurposed for attacker-controlled compute theft or cryptomining by connecting victims to malicious project servers.
Legitimate distributed computing platform referenced as being deployed alongside malware as a secondary payload (likely for resource abuse).
Legitimate distributed computing client observed in a modified form as a follow-on payload delivered by MintsLoader.
A modified BOINC client used as a follow-on payload delivered by MintsLoader (specific malicious purpose not detailed in the content).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.