DIICOT
Cryptojacking + P2P botnet (Monero) first seen 2021 6 chapters
SSH cryptojacking documented since 2021. Two generations landed on the decoy back to back, and between one and the other the whole programme changed.
DIICOT —also known as Mexals— is a veteran cryptojacking operation, documented since 2021 by Bitdefender and later by Akamai, Cado, Darktrace and Wiz. The name is the author’s own joke: it’s borrowed from a Romanian organised-crime agency. Its routine is textbook: brute-force in over SSH, evict the competition, install a Monero miner and hide it.
Two generations landed on the decoy, and they’re worth keeping apart.
The classic one —chapters 23 to 25— is the one documented for years. It hides the miner with a line in .bashrc that makes the top command lie, and it carries the wallet inside the binary, covered with toy encryption. Which is why with this one the money can be followed down to the last payout.
The 2026 build —chapters 26 to 28— changed programme entirely. Command stopped being client-server and became a peer-to-peer mesh that elects a leader, with the orders arriving over a Telegram chat; the binaries are obfuscated and packed; and the wallet no longer travels inside: it gets downloaded at start-up, from a server that dies when the campaign dies. The same family, with every door closed.
https://blog.efespain.com/en/diicot/
#malware #cryptojacking #Monero #honeypot
Remote
eFeSpain
@eFeSpain@infosec.exchange
I’m no analyst, no engineer, no hacker. Just someone very curious and self-taught. In 2004 I bought my first internet-connected PC without even knowing how to open a web page — and days later a worm called Blaster got inside it. Instead of scaring me, it fascinated me. I haven’t stopped since: by day I work with networks, VoIP and IPTV; the rest of the time I have fun with a real honeypot, and I write about it.
0 Followers
0 Following
1 Posts
Joined September 19, 2026
