Mining Gang's New Tool: k4spreader
Essential information
- Published
- 02/07/2024 08:22
- Modified
- 02/07/2024 08:50
- Tags
- 2024-07-02 botnet k4spreader mining pwnrig spreader tsunami
- Related entities
- 35 observables, 1 intrusion sets (apt), 7 techniques (mitre), 3 malware
Description
QIanxin describes the discovery and analysis of k4spreader, a new malware installer and spreader tool developed by the 8220 mining gang. k4spreader is written in cgo and implements system persistence, self-updating, and releasing other malware like the Tsunami botnet and PwnRig miner. The tool is still in early development with three versions observed so far.