PickaxePickaxe

Also known as: Prying Libra · Pickaxe

Known aliases
2

Profile

Prying Libra, also known as Pickaxe, is a threat actor active since at least August 2017, and continues to remain active to this day. The adversary's goal is to install and maintain a popular cryptocurrency miner on the victim's machine. The miner in question is an open-source tool named XMRig that generates the Monero cryptocurrency. Malware is delivered via downloads through the popular Adfly advertisement platform. Users are often mislead into clicking on a malicious advertisement that results in the payload being delivered to the victim. Once installed, the malware leverages VBS scripts and redirection services, such as bitly, to ultimately download and execute XMRig. Over 15 million confirmed victims have been discovered to be infected in recent campaigns, with actual numbers likely to be between 30-45 million victims. The victims are found across the globe, with high concentrations in Thailand, Vietnam, Egypt, Indonesia, and Turkey.

Aliases· 2

Prying LibraPickaxe

References

  1. https://unit42.paloaltonetworks.com/atoms/pryinglibra/

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
Returned Libra
Software
KingMiner
Actor
TA406
Actor
Budminer
Software
CroniX
Actor
TA516
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.