
The Blue Mockingbird hacking group is deploying a Moneroon Internet-facing Windows of multiple organizations, as discovered by Red Canary security researchers.
As found, the group has been active since December 2019 and uses many techniques to bypass security.
How did the Blue Mockingbird group operate?

Malicious actors exploited web applications that use Telerik UI for ASP.NET AJAXto gain access to machines.
Telerik UI is a user interface suite that helps in the web. Version 2019.3.1023 of the suite, however, has a vulnerability CVE-2019-18935, which was discovered and exploited by the Blue Mockingbird team to gain access to the system and then use the JuicyPotatoto escalate their privileges.
Once he managed to take full control of the device, he deployed a popular version of the Monero mining tool XMRIG as a DLL.
When the COR_PROFILER was configured, every process that loaded the Microsoft .NET Common Language Runtime established persistence.
In some cases, hackers even created a new service to perform the same actions as the COR_PROFILER payload.
Using the JuicyPotato method, the hacking group escalates its privileges from a virtual IIS Application Pool Identity account to the NT Authority \\ SYSTEM account.
Subsequently, the malicious actors use RDP to deploy payloads to remote systems.
How will you avoid such an attack?
To mitigate attacks, it is recommended to update web servers, web applications, and the components that applications. Red Canary has also published a detailed report that presents the Risk Indicators.
