logo

Qubitstrike Crypto Mining and Rootkit Campaign (Campaign)

ID: ec433816-ed73-5219-806a-2b0ff90c8227

STIX ID: report--ec433816-ed73-5219-806a-2b0ff90c8227

Feed Name: Wiz Cloud Threat Landscape

Threat Score
65/100

Date Published: 2023-10-18

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Qubitstrike is an active cryptojacking and credential-theft campaign abusing exposed Jupyter Notebook instances: attackers obtain shells, deploy a crypto-miner, persist via cron and SSH authorized_keys, install the Diamorphine rootkit to hide activity, and exfiltrate AWS/Google credentials (via Telegram bot API). Payloads are hosted on codeberg.org and a Python implant uses Discord as C2; limited attribution points to a Tunisian IP observed using stolen credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.