Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

TON Price Prediction: $1.50 Target as Technical Indicators Signal Potential 13% Rally

May 2, 2026

The Cheap Foreign Labor Regime Blocking Agricultural Intelligence

May 2, 2026

Meteora reports $1.5 million OTC scam loss in Q1 MET report

May 2, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»Research Unearths RUBYCARP’s Multi-Miner Assault on Crypto
Research Unearths RUBYCARP’s Multi-Miner Assault on Crypto
Security

Research Unearths RUBYCARP’s Multi-Miner Assault on Crypto

March 10, 2026No Comments2 Mins Read

A recent research study has shed light on the decade-long activities of a Romanian cyber threat group known as RUBYCARP, which uses techniques such as cryptocurrency mining and phishing.

One of the key findings from the technical write-up, published by Sysdig today, is the group’s use of a script capable of simultaneously deploying multiple cryptocurrency miners. 

By executing these miners concurrently, RUBYCARP reduces both the time required for the attack and the likelihood of detection. The script primarily targets XMRig/Monero miners and was previously hosted on a now-defunct domain, “download[.]c3bash[.]org.”

Further evidence suggests that RUBYCARP also conducts phishing operations to steal valuable financial assets, including credit card numbers. 

The researchers uncovered a phishing template targeting Danish users, impersonating the logistics company Bring. Moreover, a PHP script named “ini.inc” was identified as the tool used to send these phishing emails, with compromised email accounts linked to the attacks.

Further analysis of the group’s activities uncovered a variety of tools and techniques, including the use of specific commands within shell bot code to send phishing emails. The researchers also found evidence of a potential phishing landing page targeting European entities, including Swish Bank and Nets Bank, among others.

The study also highlights RUBYCARP’s involvement in the development and sale of cyber weapons.

Read more on such weapons: Russian Hacking Group Sandworm Linked to Unprecedented Attack on Danish Critical Infrastructure

“Attribution is always difficult, but they are most likely Romanian and may have some crossover with the ‘Outlaw APT’ group and others who leverage the Perl Shellbot. These threat actors are also involved in the development and sale of cyber weapons, which isn’t very common,” reads the advisory.

See also  Unraveling the Dark Side of Crypto

According to the security experts, communication among threat actors has remained broadly consistent over the years, with IRC remaining highly popular. Additionally, the community dynamic within RUBYCARP is noteworthy, as it involves mentoring newcomers to the scene. This aspect also offers financial advantages to the group, as it can later sell the toolset it has developed to them.

“While RUBYCARP targets known vulnerabilities and conducts brute force attacks, what makes it more dangerous is its post-exploitation tools and the breadth of its capabilities,” Sysdig warned. “Defending against this group requires diligent vulnerability management, a robust security posture and runtime threat detection.”

Source link

Assault Crypto MultiMiner research RUBYCARPs Unearths

Related Posts

Meteora reports $1.5 million OTC scam loss in Q1 MET report

May 2, 2026

Brazil's central bank bans stablecoin and crypto settlement in cross-border payments

May 2, 2026

Crypto hack losses top $630M in April, highest since February 2025

May 2, 2026

US seized $500M in Iranian crypto assets, Treasury secretary says

May 2, 2026
Top Posts

Sam Bankman-Fried Prosecutor Promises 'Handcuffs for All' Crypto Crooks

November 3, 2023

ISIS Calls On Muslims To Murder UK’s Tommy Robinson

April 13, 2026

Will the bitcoin hashrate stall as miners pivot to AI and reshape decentralization?

March 30, 2026

Type above and press Enter to search. Press Esc to cancel.