Researchers reported that the Lucifer malware evolved from a Windows-based cryptominer into a cross-platform threat targeting Windows, Linux, and IoT devices with a mix of Monero mining, DDoS, command-and-control, and remote execution capabilities. Check Point linked Lucifer to the earlier BlackSquid and Rudeminer/Spreadminer activity through shared code traits and Monero wallet overlaps, indicating the operators had likely been active since 2018 and were continuing to release new variants.
The campaign hit more than 25 organizations across the United States, Ireland, the Netherlands, Turkey, and India, including victims in manufacturing, legal, insurance, and banking. The malware spread by exploiting known flaws—especially CVE-2018-10561 in Dasan GPON routers—along with older Windows exploits and brute-force attacks. Researchers said Linux samples supported mining and full C2 functions, while ARM and MIPS variants were used mainly for DDoS operations, underscoring Lucifer's shift into a broader hybrid malware platform.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
The report states that the first samples of the newer Lucifer campaign were uploaded to VirusTotal in February 2020, marking the emergence of the newer campaign iteration.
Check Point reported that samples tied to the Lucifer, BlackSquid, and Rudeminer/Spreadminer-linked campaign date back to late 2018, indicating the operators likely began activity in 2018.
Check Point published research connecting Lucifer to the previously reported BlackSquid and Rudeminer/Spreadminer campaigns through shared Monero wallets, similar samples, and code traits.
ThreatCloud telemetry showed recent Lucifer activity affecting more than 25 organizations in the United States, Ireland, the Netherlands, Turkey, and India across manufacturing, legal, insurance, and banking sectors.
Check Point said the first and only ARM sample noted in the report was uploaded to VirusTotal on May 10. The sample primarily supported DDoS capabilities and was not detected as malicious at the time referenced.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 16 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.