Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to malware
Malware

Troj/GoMiner-B

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

7 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1195Supply Chain CompromiseEvidence2

Sygnia’s findings confirmed this was a supply chain compromise... The issue did not appear in every single test run... suggesting that the binary was being pushed through the update distribution pipeline under specific conditions.

Execution

1 technique
T1053Scheduled Task/JobEvidence1

...creates a service with the name hola_monitor_svc, configured to autostart and run when the host is idle.

Persistence

3 techniques
T1053Scheduled Task/JobEvidence1

...creates a service with the name hola_monitor_svc, configured to autostart and run when the host is idle.

T1543.003Windows ServiceEvidence2

When run with administrative rights, the file copies itself to a new path within the Hola directory and registers itself as a Windows service named hola_monitor_svc. This service is set to autostart...

T1547Boot or Logon Autostart ExecutionEvidence1

This service is set to autostart and activates specifically when the host machine is idle...

Privilege Escalation

3 techniques
T1053Scheduled Task/JobEvidence1

...creates a service with the name hola_monitor_svc, configured to autostart and run when the host is idle.

T1543.003Windows ServiceEvidence2

When run with administrative rights, the file copies itself to a new path within the Hola directory and registers itself as a Windows service named hola_monitor_svc. This service is set to autostart...

T1547Boot or Logon Autostart ExecutionEvidence1

This service is set to autostart and activates specifically when the host machine is idle...

Stealth

1 technique
T1036MasqueradingEvidence2

The file, named me.exe, was not part of the browser’s declared software package, and it appears to have been silently dropped onto users’ systems without their knowledge or consent.

Impact

1 technique
T1496Resource HijackingEvidence2

The me.exe binary appears to be based on XMRig, a well-known open-source crypto-mining tool... activates specifically when the host machine is idle... designed to run quietly in the background at all times.

Other

1 technique
T1562.001Disable or Modify ToolsEvidence2

To avoid detection, the binary also performed a Windows Defender exclusion, effectively asking the operating system to ignore its presence entirely.

INDICATORS OF COMPROMISE

IOCs tracked for this family

1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Hashes
1 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
hash.sha256●●●●●●●●●●●●View more in app14 days ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching1

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping7

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.