MyKings is a long-running Windows botnet and cryptomining malware operation active since at least 2016. It is also widely associated with the names Smominru and DarkCloud. The malware ecosystem is modular and has included components for bootkit functionality, droppers, coin miners, and clipboard-stealing theft modules, indicating an adaptable criminal platform focused on monetization and persistence at scale.
MyKings is best known for large-scale cryptocurrency mining and for a clipboard stealer that monitors clipboard contents and replaces selected values with attacker-controlled alternatives. Observed replacement targets include cryptocurrency wallet strings, Steam trade offer links, and Yandex Disk sharing links. This enabled both direct cryptocurrency theft and fraud involving digital goods, while also supporting further malware distribution through substituted file-sharing links.
The malware has been linked to Windows-based installer and script chains that deploy both mining payloads and the clipboard stealer. Reporting has also tied MyKings activity to attacks against Microsoft SQL Server environments, where attackers abuse SQL Server features such as OLE Automation and CLR stored procedures to download and execute MyKings payloads. Broader Smominru/MyKings activity has additionally been associated with wormable propagation through SMB exploitation, especially EternalBlue against vulnerable Windows systems, contributing to very large botnet growth.
MyKings has targeted Windows hosts globally, with notable victim concentrations reported in countries including Russia and India. The operation has primarily pursued financially motivated objectives through Monero mining and other cryptocurrency abuse, but its modular design and use of droppers and persistence mechanisms make it a broader post-compromise malware platform rather than a single-purpose miner.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
CoinHelper is mostly bundled with cracked software installers such as WinRAR and game cheats... We’ve also found this threat inside a Windows 11 ISO image from unofficial sources... We have even seen this threat bundled with clean software such as Logitech drivers for webcams.
For protection against quick analysis and against static extraction with regular expressions, the substitute values are encrypted. Encryption used is a very simple ROT cipher, where the key is set to -1.
The main purpose of the clipboard stealer is rather simple: checking the clipboard for specific content and manipulating it in case it matches predefined regular expressions... This process of swapping is done using functions OpenClipboard, EmptyClipboard, SetClipboardData and CloseClipboard. | It is easy to notice when someone forgets to copy and paste something completely different... but it takes special attention to notice the change of a long string of random numbers and letters to a very similar looking string, such as cryptowallet addresses.
23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a known miner family whose attack techniques may resemble those used to deploy MrbMiner.
CoinMiner ecosystem that compromises MS-SQL servers (including via OLE automation and CLR assemblies) to fetch additional payload URLs, beacon basic host info to C2, and download/execute files or shellcode.
A botnet referenced here as distributing a clipboard stealer that sometimes delivered CoinHelper, though the article explicitly says CoinHelper cannot be attributed to MyKings.
A long-running botnet with multiple modules. This article focuses on its clipboard stealer component, which monitors clipboard contents and swaps cryptocurrency wallet addresses, Steam trade offer links, and Yandex Disk links to attacker-controlled values for fraud, monetization, and further malware distribution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.