MikuBot Spotted In The Wild
ID: 1038a9e7-137b-5511-bade-601b71f4b59f
STIX ID: report--1038a9e7-137b-5511-bade-601b71f4b59f
Feed Name: Cyble Blog
Cyble Research Labs discovered and analyzed MikuBot, a C++ Windows malware sold on underground forums that performs data theft, hidden VNC remote access (HVNC), USB propagation, and downloader functionality. The report details technical behavior (resource RCData payload, UPX unpacking, mutex, persistence via scheduled tasks and startup shortcut), PowerShell commands used to disable Defender and kill competing miners, anti-analysis checks, the C2 endpoint (136.144.41.244/panel/gate.php?CBB536F139732610633691), and provides multiple file hashes and panel screenshots as IOCs and operational context.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
