RUBYCARP: Botnet Exploiting Vulnerabilities for Crypto (Campaign)
ID: 3694052e-c960-595f-914f-531483a8b4d4
STIX ID: report--3694052e-c960-595f-914f-531483a8b4d4
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2024-04-09
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
RUBYCARP is a long-running Romanian criminal botnet operation focused on financial gain through cryptomining, phishing, DDoS and resource hijacking. The group deploys public vulnerability exploits and brute-force attacks, uses IRC for command-and-control, maintains a broad post-exploitation toolset (including XMRig, ShellBot/PerlBot, C3Bash), and also develops and markets malware to other criminals, increasing its reach and persistence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
