Qubitstrike Crypto Mining and Rootkit Campaign (Campaign)
ID: ec433816-ed73-5219-806a-2b0ff90c8227
STIX ID: report--ec433816-ed73-5219-806a-2b0ff90c8227
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2023-10-18
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Qubitstrike is an active cryptojacking and credential-theft campaign abusing exposed Jupyter Notebook instances: attackers obtain shells, deploy a crypto-miner, persist via cron and SSH authorized_keys, install the Diamorphine rootkit to hide activity, and exfiltrate AWS/Google credentials (via Telegram bot API). Payloads are hosted on codeberg.org and a Python implant uses Discord as C2; limited attribution points to a Tunisian IP observed using stolen credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
