Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Национальный центр кибербезопасности Нидерландов (NCSC) предупредил, что злоумышленники начали эксплуатировать критическую уязвимость CVE-2026-65400 в macOS Screen Sharing. Баг позволяет обойти аутентификацию, получив доступ к Mac без пароля, и уже применяется в реальных атаках для установки майнера Monero.
The CVE-2019-18935 vulnerability, with its critical 9.8 severity score, is an untrusted deserialization vulnerability within the proprietary Progress Telerik UI (for ASP.NET AJAX) library... While originally published in December 2019, the flaw continues to be exploited even today despite patches and fixes having been made available.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
Apple patched the macOS Screen Sharing issue on August 6, warning that it could allow attackers to bypass authentication and log into vulnerable devices without valid credentials.
Проблема CVE-2026-65400 затрагивает встроенную в macOS функцию Screen Sharing... Для соединения в этом случае используется VNC через TCP-порт 5900.
Apple patched the macOS Screen Sharing issue on August 6, warning that it could allow attackers to bypass authentication and log into vulnerable devices without valid credentials.
Check for the Trend Micro cryptominer indicators, unexpected outbound connections, new SSH keys or authorized_keys entries, unfamiliar persistence
Проблема CVE-2026-65400 затрагивает встроенную в macOS функцию Screen Sharing... Для соединения в этом случае используется VNC через TCP-порт 5900.
Threat actors were seen abusing it to gain root access and deploy a Monero miner.
Apple patched the macOS Screen Sharing issue on August 6, warning that it could allow attackers to bypass authentication and log into vulnerable devices without valid credentials.
Check for the Trend Micro cryptominer indicators, unexpected outbound connections, new SSH keys or authorized_keys entries, unfamiliar persistence
Анализ показал, что этот компонент не проходил сертификацию, не имел цифровой подписи и временных меток, содержал обфусцированный код и обладал возможностями для записи в память.
Impact, cryptojacking (TA0040) Monero miner renamed and dropped to a hidden path, launched in background, staged via public file-share
28 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A disguised cryptomining payload deployed to compromised hosts for illicit revenue generation.
A cryptomining payload deployed after exploitation to mine Monero on compromised macOS systems.
Cryptomining malware noted as co-infecting some victims during the same period, but not the main focus of the report.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.