Blue Mockingbird Cryptocurrency Campaign
Beginning in December 2019, Blue Mockingbird is a cryptocurrency mining group and campaign targeting exposed ASP.NET web servers.
Summary
Beginning in December 2019, Blue Mockingbird is a cryptocurrency mining group and campaign targeting exposed ASP.NET web servers.
Affected platforms
The following platforms are known to be affected:
- Progress Telerik UI for ASP.NET AJAX - Versions 2019.3.1023 and earlier
Threat details
Blue Mockingbird attacks begin with identification of vulnerable versions of the Telerik UI running on public-facing ASP.NET systems. An exploit is then deployed to install a web shell on the targeted system, before using the Juicy Potato technique to provide it with administration privileges. Once this is done, Blue Mockingbird log into the shell to install copy of the XMRig mining application. They may also attempt to propagate to other systems over RDP or SMB if possible.
For further information:
Remediation steps
| Type | Step |
|---|---|
|
Telerik address the vulnerability exploited by Blue Mockingbird in their UI for ASP.NET AJAX R1 2020 release. Affected organisations are encouraged to apply this update immediately. Additionally, to prevent and detect an infection, NHS Digital advises that:
Please note that NCSC maintains guidance for securely configuring a wide range of end user device (EUD) platforms. For further details refer to their end user device security guidance pages. |
Indicators of compromise
CVE Vulnerabilities
Last edited: 29 June 2021 12:01 pm