📅 Day 59 — Studying Malware Families: TrickBot, WannaMine and Cryptomining Threats
🎯 Goal
Today I explored several real malware families to understand how modern threats operate.
The focus was on:
- TrickBot
- WannaMine
- PyRoMineIoT
The objective was to learn how these threats behave and how defenders identify them.
🛠 What I Did
I studied several well-known malware families that have appeared in real-world attacks.
TrickBot
TrickBot began as a banking trojan, but over time it evolved into a full modular malware platform.
Capabilities include:
- credential theft
- network reconnaissance
- lateral movement
- deployment of additional malware.
TrickBot has often been used as an entry point for larger attacks, including ransomware operations.
Typical attack chain:
Initial infection
↓
TrickBot establishes persistence
↓
network discovery begins
↓
additional payloads deployed
WannaMine
WannaMine is a fileless cryptomining malware.
Instead of encrypting files like ransomware, it hijacks system resources to mine cryptocurrency.
Key characteristics include:
- heavy use of PowerShell
- lateral movement within networks
- CPU resource exhaustion.
Because it operates in memory and uses legitimate system tools, it can be difficult to detect.
PyRoMineIoT
PyRoMineIoT is another cryptomining malware variant targeting vulnerable systems.
These types of threats typically exploit:
- weak credentials
- exposed services
- vulnerable IoT devices.
Once inside a system, the malware installs cryptocurrency mining software.
🔗 Key Cybersecurity Connections
These malware families highlight common attacker strategies:
- modular malware frameworks
- lateral movement across networks
- abuse of system resources
- stealth techniques to avoid detection.
Security teams detect these threats through:
- unusual CPU usage
- suspicious PowerShell activity
- network scanning behavior
- connections to known mining pools.
🔍 Investigation Questions
If activity related to these malware families appeared in telemetry, a SOC analyst might ask:
- Which process initiated the suspicious activity on the host?
- Was PowerShell executed with unusual command-line arguments?
- Did the system start consuming abnormal CPU resources suddenly?
- Were there outbound connections to known cryptocurrency mining pools?
- Did the host attempt lateral movement to other systems on the network?
- Are multiple endpoints showing similar behavioral patterns?
These questions help analysts determine whether suspicious activity is part of a coordinated malware infection.
🚨 Detection Opportunities
Possible detection strategies for these threats include:
- monitoring abnormal CPU utilization spikes across endpoints
- detecting suspicious or encoded PowerShell command execution
- identifying systems performing network scanning or lateral movement
- alerting on outbound connections to known mining pool domains or IPs
- detecting processes spawning unusual child processes associated with cryptomining activity
Behavioral monitoring is particularly important because many modern malware families operate in memory or using legitimate system tools.
🧭 MITRE ATT&CK Techniques
These malware families often relate to several ATT&CK techniques:
- T1059 – Command and Scripting Interpreter (PowerShell usage)
- T1027 – Obfuscated/Compressed Files and Information
- T1105 – Ingress Tool Transfer
- T1046 – Network Service Discovery
- T1496 – Resource Hijacking (cryptomining activity)
Mapping activity to ATT&CK techniques helps defenders understand how malware operates across different stages of an attack.
⚠ Challenges
Modern malware often avoids traditional detection techniques.
Instead of dropping obvious malicious files, attackers frequently rely on:
- scripts
- legitimate system tools
- in-memory execution.
This makes behavior-based detection increasingly important.
📚 What I Learned
Important lessons from studying these malware families:
- many threats evolve into modular platforms
- attackers frequently reuse infrastructure and techniques
- detection often relies on observing abnormal system behavior.
➡ Next Steps
Future learning areas include:
- malware persistence techniques
- command-and-control infrastructure
- detection rules for suspicious process behavior.
🧠 Reflection
Studying real malware families helps connect theory with real-world threats.
Understanding attacker behavior makes it easier to recognize suspicious patterns during investigations.
🧩 Lessons Learned
What worked
Studying multiple malware families revealed recurring patterns in attacker tactics.
What broke
Initially these threats seemed unrelated.
Why it broke
Many malware families reuse similar techniques and infrastructure.
Fix / takeaway
Focus on behavioral patterns rather than individual malware names.
📈 Skill Progression Context
Learning about real malware families strengthens:
- threat intelligence understanding
- SOC investigation skills
- detection engineering knowledge.
This builds on earlier study of:
- phishing attacks
- LOLBins
- Windows process execution techniques.
