Researchers detailed the Rarog cryptocurrency-mining Trojan, a malware family sold on underground forums and used by multiple threat actors to mine Monero. Analysis of roughly 2,500 unique samples found the malware communicating with 161 command-and-control servers and infecting more than 166,000 systems globally, with the largest concentrations in the Philippines, Russia, and Indonesia. Evidence linked the operation to the online handles arsenkooo135 and foxovsky, and suggested Rarog may be a rebranded version of the earlier DiscordiaMiner malware.
Rarog was built with broader botnet capabilities beyond coin mining, including persistence, USB propagation, configurable miner settings, DLL/module loading, malware download functions, DDoS support, self-updating, and self-deletion. The malware was reportedly marketed for about 6,000 rubles, but despite its wide reach, observed criminal returns were limited: the most profitable operator identified by researchers earned only about 0.58 Monero and 54 ByteCoin, worth roughly $123.68 at the time.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Kaspersky previously described a similar cryptocurrency miner called DiscordiaMiner and attributed it to the same "foxovsky" user. Unit 42 later cited code overlap and assessed that Rarog was likely an evolution or rebranding of DiscordiaMiner.
Unit 42 reported that the distribution of new Rarog samples peaked during the week of September 11, 2017, when researchers encountered 187 unique samples. This marked the highest observed weekly volume of new Rarog samples in their dataset.
Rarog was advertised for sale on Russian-speaking criminal underground sites, with a listed price of 6,000 rubles and a guest administration panel offered to prospective buyers. The report states the malware had been sold since June 2017.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.