Rarog is a cryptocurrency-mining Trojan that has been sold on Russian-speaking underground forums since 2017 and used by multiple criminal operators. It is primarily associated with illicit Monero mining, although it supports mining of other cryptocurrencies as well. The malware was marketed as a commodity offering with an administration panel and was linked to the online handles foxovsky and arsenkooo135. Reporting has also assessed that Rarog is likely an evolution or rebranding of the earlier DiscordiaMiner malware.
Rarog combines coin-mining functionality with broader botnet features. It can download mining software, configure miner parameters, adjust processor usage, collect mining statistics, and throttle activity based on characteristics of the infected host. Beyond mining, it supports downloading and executing additional malware, loading supplementary DLL modules, updating itself, deleting itself, and launching distributed denial-of-service activity. It also includes USB propagation functionality, expanding its ability to spread beyond the initially compromised host.
On infected Windows systems, Rarog establishes persistence through multiple mechanisms including autorun-style startup and scheduled execution. It communicates with command-and-control infrastructure over HTTP and supports tasking related to configuration, updates, module delivery, blacklisting, and CPU-core management. Large-scale telemetry associated with the malware showed substantial global victimization, with especially high infection volumes observed in the Philippines, Russia, and Indonesia. Despite broad distribution, observed operator profits were relatively low, indicating that the malware was widely deployed but not especially lucrative in the measured campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
foxovsky as being the author of a previously reported malware family called Rarog.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The following command is executed to create a Scheduled Task to run the checker.vbs script periodically... The following command is executed to create a Scheduled Task to run Isass.exe periodically
@ echo off powershell - WindowStyle Hidden - ExecutionPolicy Bypass - NoP - file C : \ ProgramData \ WindowsAppCertification \ WindowHelperStorageHostSystemThread . ps1
The contents of checker.vbs is as follows: Set WshShell = CreateObject ( "WScript.Shell" ) WshShell . Run "C:\ProgramData\WindowsAppCertification\cert.cmd" , 0
The following command is executed to create a Scheduled Task to run the checker.vbs script periodically... The following command is executed to create a Scheduled Task to run Isass.exe periodically
The following command is executed to create a Scheduled Task to run the checker.vbs script periodically... The following command is executed to create a Scheduled Task to run Isass.exe periodically
Prior to running the miner, Rarog will check the running processes on the system for the following strings... Rarog continues to make a request to '/4.0/method/blacklist' determine what processes should be blacklisted.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously reported malware family attributed in the article to foxovsky, mentioned as part of the broader criminal community around TheBottle.
Next: Smoking Out the Rarog Cryptocurrency Mining Trojan
Cryptocurrency-mining trojan primarily used to mine Monero that also includes botnet capabilities such as persistence, USB spreading, downloading and executing additional malware, DDoS, updating itself, and loading additional DLL modules.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.