logo

APT3__2020__KR_Analysis_Report_MyKings_Botnet.pdf

ID: a828eb0e-6654-4b43-a37f-6ba68cd6638a

STIX ID: report--a828eb0e-6654-4b43-a37f-6ba68cd6638a

Threat Score

78/100

Uploaded: 2026-08-14

Published Date: 2020-03-02

Last Modified Date: 2020-03-02

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This AhnLab analysis documents the MyKings botnet (aka DarkCloud/Smominru/Hidden), detailing a multi-stage infection chain that uses downloaders (cab.exe, msinfo.exe), backdoors (item.dat), setting modifiers (msief.exe, c3.bat, n.vbs), an MBR bootkit for persistence and anti‑AV, and final-stage coin miners (and historically Mirai payloads). The report highlights certificate theft/forgery used to sign malware, extensive IoCs (filenames, thousands of hashes, C2/download URLs), observed TTPs (SQL brute-force, EternalBlue, FTP/HTTP/PowerShell delivery), infection symptoms, and AhnLab detection names and recommendations.