Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
To achieve persistence, KryptoCibule creates a scheduled task to be run every five minutes ... schtasks.exe /CREATE /SC MINUTE /MO 5 /TN " Adobe Update Task "
Among the commands it supports are EXEC, which allows execution of arbitrary commands and SHELL, which downloads a PowerShell script from the C&C.
MITRE ATT&CK techniques ... T1059.003 Command and Scripting Interpreter: Windows Command Shell Commands received from the KryptoCibule C&C are executed with cmd.exe.
This file is scrambled with the open source program Obfuscar. This same tool is used on all of the malware's custom executables.
The malware is then installed to the hardcoded path %ProgramFiles(x86)%\Adobe\Acrobat Reader DC\Reader\update and uses legitimate Adobe Acrobat Reader executable names for the bundled Tor executable and its own.
MITRE ATT&CK techniques ... T1036.004 Masquerading: Masquerade Task or Service KryptoCibule tasks are named after legitimate and benign looking software.
KryptoCibule uses paths and filenames that match those of Adobe Reader for malware and Tor client.
Both are XOR-encrypted with keys contained in Setup.exe. When Setup.exe is executed, it decodes both the malware and the expected installer files.
Before first executing its payload and on every iteration of the main loop, the malware performs a check for running analysis software ... If any process with a matching name is found, it stops all running components and exits.
KryptoCibule uses System.Diagnostics.Process.GetProcesses to get a list of running processes.
KryptoCibule obtains information about host’s timezone, locale, power status, OS and hardware.
The third component walks through the filesystem of each available drive and looks for filenames that contain certain terms.
Before first executing its payload and on every iteration of the main loop, the malware performs a check for running analysis software ... If any process with a matching name is found, it stops all running components and exits.
One of these provides a REST API that the malware uses for most communications ... KryptoCibule uses HTTP for C&C communication.
MITRE ATT&CK techniques ... T1071.002 File Transfer Protocols KryptoCibule downloads updates and additional tools via BitTorrent.
This sets up a SOCKS proxy on port 9050 that is used by the malware to relay all communications with the C&C servers through the Tor network.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cryptocurrency-focused malware spread via a local file-sharing service while masquerading as pirated games or DLC.
KryptoCibule is referenced as an earlier crypto-mining trojan with strong design similarities to Clipminer, possibly as a precursor, inspiration, or related evolution.
A C# malware family active since at least December 2018 that targets cryptocurrency users by mining coins on victim systems, hijacking clipboard wallet addresses, exfiltrating cryptocurrency-related files, and providing remote access capabilities. It spreads via malicious torrents masquerading as cracked or pirated software installers, uses Tor and BitTorrent for communications and updates, and employs multiple anti-detection and persistence techniques.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.