CSIDB logo
Threat actor

Blue Mockingbird

Attribution profile

Type
Criminal
Location
Russia
Known incidents
2 incidents
First seen
2022-06-01
Last seen
2022-06-01
Updated
2026-08-01 01:10
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Blue Mockingbird is a threat actor tracked under that alias, with open‑source reporting indicating the group operates from Russia. The actor first came to public attention in 2020 when it exploited outdated Telerik UI components on Microsoft IIS servers to install cryptocurrency miners, and it resumed similar activity in mid‑2022. No additional names or affiliated groups have been publicly attributed to Blue Mockingbird in the sources reviewed.

The actor’s primary targets are web applications that rely on the Telerik UI library for ASP.NET AJAX, regardless of industry sector, because the vulnerability resides in a widely used third‑party component. By compromising these servers, Blue Mockingbird seeks financial gain through the covert mining of Monero, a privacy‑focused cryptocurrency, as evidenced by the deployment of XMRig miners in both the 2020 and 2022 campaigns. While the immediate goal is resource hijacking for profit, the use of Cobalt Strike beacons demonstrates a capability to enable lateral movement, data exfiltration, or further payload delivery if the actors choose to expand their objectives.

Initial access is achieved by exploiting a critical deserialization flaw in Telerik UI, identified as CVE‑2019-18935, after acquiring the application’s encryption keys—either through a separate vulnerability in the target web app or via leveraging older flaws such as CVE‑2017-11317 and CVE‑2017-11357. Once the keys are obtained, the actors use a publicly available proof‑of‑concept exploit to compile a malicious DLL that runs within the w3wp.exe process, delivering a Cobalt Strike beacon for command and control. Persistence is established through Group Policy Objects that create scheduled tasks executing base64‑encoded PowerShell scripts, which employ AMSI‑bypass techniques to evade Windows Defender and load the beacon into memory. The secondary payload is the XMRig miner, which hijacks CPU cycles to generate Monero for the actor’s financial benefit.

Attribution to Russia is based on the location information provided in the threat actor context, but the sources do not specify any state sponsorship, criminal consortium, or broader affiliations beyond the geographic origin. The described campaigns represent the actor’s known operational pattern: repeated exploitation of the same Telerik UI weakness to deploy stealthy beacons and cryptocurrency miners, with the underlying infrastructure remaining consistent across observed incidents. No further details about the actor’s size, sophistication, or revenue are available in the supplied material.

Incidents

Attributed incidents are available to members.

2 incidents
CSIDB