logo

MikuBot Spotted In The Wild

ID: 1038a9e7-137b-5511-bade-601b71f4b59f

STIX ID: report--1038a9e7-137b-5511-bade-601b71f4b59f

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2022-08-11

Date Updated: 2026-07-17

...
...

Cyble Research Labs discovered and analyzed MikuBot, a C++ Windows malware sold on underground forums that performs data theft, hidden VNC remote access (HVNC), USB propagation, and downloader functionality. The report details technical behavior (resource RCData payload, UPX unpacking, mutex, persistence via scheduled tasks and startup shortcut), PowerShell commands used to disable Defender and kill competing miners, anti-analysis checks, the C2 endpoint (136.144.41.244/panel/gate.php?CBB536F139732610633691), and provides multiple file hashes and panel screenshots as IOCs and operational context.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.