Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

Seoul Court Rescues Bithumb from Record 6-Month Suspension

May 2, 2026

Bitdeer Sells All Mined BTC This Week: Zero-Holding Strategy Intensifies

May 2, 2026

How North Korean spies spent months in-person to drain $285 million from Drift

May 2, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»Research Unearths RUBYCARP’s Multi-Miner Assault on Crypto
Research Unearths RUBYCARP’s Multi-Miner Assault on Crypto
Security

Research Unearths RUBYCARP’s Multi-Miner Assault on Crypto

March 10, 2026No Comments2 Mins Read

A recent research study has shed light on the decade-long activities of a Romanian cyber threat group known as RUBYCARP, which uses techniques such as cryptocurrency mining and phishing.

One of the key findings from the technical write-up, published by Sysdig today, is the group’s use of a script capable of simultaneously deploying multiple cryptocurrency miners. 

By executing these miners concurrently, RUBYCARP reduces both the time required for the attack and the likelihood of detection. The script primarily targets XMRig/Monero miners and was previously hosted on a now-defunct domain, “download[.]c3bash[.]org.”

Further evidence suggests that RUBYCARP also conducts phishing operations to steal valuable financial assets, including credit card numbers. 

The researchers uncovered a phishing template targeting Danish users, impersonating the logistics company Bring. Moreover, a PHP script named “ini.inc” was identified as the tool used to send these phishing emails, with compromised email accounts linked to the attacks.

Further analysis of the group’s activities uncovered a variety of tools and techniques, including the use of specific commands within shell bot code to send phishing emails. The researchers also found evidence of a potential phishing landing page targeting European entities, including Swish Bank and Nets Bank, among others.

The study also highlights RUBYCARP’s involvement in the development and sale of cyber weapons.

Read more on such weapons: Russian Hacking Group Sandworm Linked to Unprecedented Attack on Danish Critical Infrastructure

“Attribution is always difficult, but they are most likely Romanian and may have some crossover with the ‘Outlaw APT’ group and others who leverage the Perl Shellbot. These threat actors are also involved in the development and sale of cyber weapons, which isn’t very common,” reads the advisory.

See also  Ethereum-Based Altcoin Explodes 40% in 24 Hours As Crypto Whale Rapidly Accumulates: On-Chain Data

According to the security experts, communication among threat actors has remained broadly consistent over the years, with IRC remaining highly popular. Additionally, the community dynamic within RUBYCARP is noteworthy, as it involves mentoring newcomers to the scene. This aspect also offers financial advantages to the group, as it can later sell the toolset it has developed to them.

“While RUBYCARP targets known vulnerabilities and conducts brute force attacks, what makes it more dangerous is its post-exploitation tools and the breadth of its capabilities,” Sysdig warned. “Defending against this group requires diligent vulnerability management, a robust security posture and runtime threat detection.”

Source link

Assault Crypto MultiMiner research RUBYCARPs Unearths

Related Posts

How North Korean spies spent months in-person to drain $285 million from Drift

May 2, 2026

Crypto industry backs CLARITY Act yield compromise, pushes Senate Banking for markup

May 2, 2026

Meteora reports $1.5 million OTC scam loss in Q1 MET report

May 2, 2026

Brazil's central bank bans stablecoin and crypto settlement in cross-border payments

May 2, 2026
Top Posts

Chinese Oil Firms Turn To Iran To Replace Venezuelan Crude

February 3, 2026

A Cryptocurrency Platform is Suspected of Being Hacked

March 8, 2026

Operation First Light Seizes $257m in Global Scam Bust

March 7, 2026

Type above and press Enter to search. Press Esc to cancel.