Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Adylkuzz leverages EternalBlue, the same security flaw that WannaCry ransomware used to destructive effect | This year’s notable cryptocurrency-mining malware so far are Adylkuzz, CPUMiner/EternalMiner, and Linux.MulDrop.14. All exploit vulnerabilities. Adylkuzz leverages EternalBlue...
6 distinct techniques documented for this family, organized by ATT&CK tactic.
The Adylkuzz sample is protected by the VMProtect obfuscator. VMProtect is a virtualization-based obfuscator ... many other identified functions implement the instruction semantics handler of the virtualization-based obfuscation (VM handler) within a single basic block. | other code obfuscation techniques such as opaque predicates, complex arithmetic encodings or virtualization ... Our goal is to develop heuristics that pinpoint code which shares similar characteristics to obfuscated code. | code obfuscation tries to confuse disassemblers by introducing opaque control transfers to addresses that are in the middle of valid instructions ... we found two instructions overlap. | other code obfuscation techniques such as opaque predicates ... VMProtect is a virtualization-based obfuscator that heavily relies on opaque predicates thwarting disassemblers with instruction overlapping/disalinged control flow.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cryptocurrency-mining malware that infects devices and turns them into monero-mining botnets.
Adylkuzz is discussed as a malware sample protected with VMProtect, using virtualization-based obfuscation, opaque predicates, overlapping instructions, dead code, VM initialization routines, VM handlers, and hidden/decrypted API calls.
Referenced only as a comparison point for the size/hash power of Smominru.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.