Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

MyKings is a financially motivated botnet reported under the names Smominru and DarkCloud. Historical analyses describe a changing Windows infection chain: exposed services and vulnerable servers could be targeted, staged downloaders delivered different payloads, and several persistence mechanisms helped some variants survive reboot. Its reported effects included cryptocurrency mining, clipboard-jacking, and delivery of other malware. Those reports explain why an infection can take more than deleting one file to investigate and remediate; they do not establish MyKings’ present-day prevalence or the current validity of old indicators.

What is the MyKings botnet?

MyKings is the name used for a Windows-focused botnet documented in analyses by Darktrace, Sophos, and Trend Micro. Those sources also associate it with the names Smominru and DarkCloud. Darktrace says verified attribution remains elusive, so the names describe the reported malware activity rather than establishing who operated it.

A botnet is a collection of compromised systems that can be directed or used by its operators. In the MyKings reporting, the activity was financially motivated, with cryptocurrency mining among the documented purposes. Researchers also reported other malware and remote-access capabilities, so mining was not the only security concern.

The technical details below are historical observations of particular incidents, samples, and variants. They should not be read as a definitive description of every MyKings infection or as evidence of its current activity level.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How did MyKings reach Windows systems?

Exposed services and weak credentials

Darktrace describes targeting of Windows-based servers running services that included MySQL, MS-SQL, Telnet, SSH, IPC, WMI, and Remote Desktop. Its customer-network account describes brute-force attempts and exploitation of unpatched vulnerabilities on exposed servers. In one incident, an internet-facing SQL server received an unusual volume of connections. Darktrace said this could indicate exploitation or password brute forcing; it did not establish which was the exact initial access route in that case.

Exploitation in historical reporting

Sophos’s 2020 account says the operators preferred cracking SQL servers or using the EternalBlue exploit over spreading through topical email lures. EternalBlue is therefore part of the historical reporting, not a claim that it is a current or universal MyKings entry method. The sources describe a mix of access approaches rather than one fixed route into every system.

How did the infection chain deliver its components?

Staged downloads and modular installers

The analyzed samples were described as a sequence of scripts, downloaders, and packages rather than one self-contained file. Sophos documented a WinRAR self-extracting package that dropped another package. An installer script named c3.bat was launched by n.vbs; one layer updated bootkit configuration, while an inner layer carried cryptocurrency-miner configuration. The report also describes an EternalBlue module that ran a downloader script to retrieve later stages.

Trend Micro’s 2019 analysis describes a variant whose scripts fetched components from remote servers. Its main downloader retrieved command-and-control server addresses and additional payloads. These descriptions show why an initial detection or a single recovered file may reveal only part of the activity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Configuration could change separately

Sophos reported that the miner’s configuration could be updated without replacing the miner executable. Principal malware researcher Gabor Szappanos described the design this way: “The botnet operators try to establish a mechanism to easily update the wallet info, without replacing the miner executable itself.” That observation applies to the behavior documented in the Sophos analysis, not necessarily to every sample.

How did MyKings maintain persistence?

The reports describe persistence at several Windows layers. Trend Micro’s analyzed variant modified the master boot record (MBR), saved the original MBR elsewhere, and wrote code to disk sectors. Its analysis also documented registry entries, scheduled tasks, and Windows Management Instrumentation (WMI) objects or listeners. Darktrace likewise summarizes bootkit behavior, registry run keys, scheduled tasks, WMI listeners, and execution after reboot among reported techniques.

Host layer Reported mechanism Why it matters during investigation
Boot MBR modification and code written to disk sectors in Trend Micro’s analyzed variant Checking only files that load after sign-in may miss boot-level changes.
Registry Registry autoruns or run keys Removing a visible autorun does not establish that other persistence is absent.
Task Scheduler Scheduled tasks Review task creation and execution alongside file and endpoint evidence.
WMI WMI objects or listeners Inspect WMI-related persistence as a distinct host layer rather than treating it as a conventional startup file.

Trend Micro warned that deleting visible persistence mechanisms would not completely remove the infection in the variant it analyzed, whose infection cycle could repeat after restart. That is a variant-specific finding, but it illustrates the general investigative risk: a cleaned-up symptom is not proof that all persistence has been removed.

What payloads and effects were reported?

  • Cryptocurrency mining: Sophos and Trend Micro describe miner components. Mining consumes compromised systems’ processing capacity and can affect availability and performance.
  • Other malware and access capability: Darktrace and Trend Micro report trojans and backdoors among the payloads associated with MyKings. An infected host may therefore warrant investigation beyond the mining process itself.
  • Clipboard-jacking: Darktrace notes a clipboard-jacking module found by researchers in 2019. It replaced a copied cryptocurrency wallet address with an operator-controlled address, creating a risk at the point a user pasted a payment destination.

These payloads were reported across analyses and variants; the sources do not establish that every infected machine carried every component. The broader security impact is the combination of lost computing resources, possible additional malware or remote access, and the investigative work needed to determine what actually ran on a particular host.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What do the reported infection counts mean?

The estimates below use different measures and reporting periods; they are not interchangeable or a live count of current infections.

Reported figure Source and scope How to interpret it
More than 520,000 infections worldwide Darktrace; its article says MyKings had been active and spreading since 2016, but the reporting period for this cumulative figure is not established in the reviewed page. A historical cumulative estimate, not a current prevalence figure.
About 40,000 unique bots at a given time; more than 175,000 systems infected that year Sophos, 2020 article. The first is a point-in-time bot estimate and the second is a yearly infection figure in that article; neither is the same metric as Darktrace’s cumulative estimate.

Trend Micro’s 2019 analysis also cites BleepingComputer’s early-2018 reporting of more than 500,000 infected machines and the equivalent of US$2.3 million mined. That is a secondary figure cited by Trend Micro, not a direct Trend Micro measurement, and it is not a present-day total.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How can defenders investigate a suspected MyKings infection?

Build a timeline that joins network, endpoint, and persistence evidence instead of relying on a single alert or file. Darktrace’s incident account links unusual SQL connections with later HTTP communications and attempted payload transfer; Trend Micro’s analysis emphasizes correlating apparently separate indicators and examining persistence across Windows layers.

  1. Establish the initial activity window. Review firewall, server, and network telemetry for unusual inbound activity to exposed services, including SQL, remote administration, and other services relevant to the host. Treat a burst of connections as a lead, not proof of a particular exploit or password attack.
  2. Correlate outbound activity and downloads. Check whether the same host later made unusual HTTP connections, retrieved scripts or packages, or attempted to transfer payloads. Link times, processes, and systems where telemetry allows.
  3. Examine endpoint and payload evidence. Look for downloader and installer activity, miner behavior, and signs of trojans or backdoors. Do not assume that finding a miner accounts for all activity on the host.
  4. Review persistence by layer. Assess boot-level changes, registry autoruns, scheduled tasks, and WMI-related objects or listeners. A single deleted file or startup entry is not a complete persistence review.
  5. Validate indicators before operational use. The reports contain historical infrastructure details and sample artifacts. Check any domain, address, detection name, or artifact against current threat intelligence and the relevant environment before using it to block, hunt, or make an attribution.
  6. Plan remediation around the findings. Preserve relevant evidence, contain affected systems according to incident-response procedures, and verify that persistence and payloads have been addressed before returning a system to service. Where boot-level modification is suspected, include boot integrity in the remediation decision rather than treating file deletion as sufficient.

Why does MyKings matter to defenders?

MyKings is a useful example of why malware investigations should follow behavior across layers. A server can first show suspicious access attempts, then downloader activity, then a payload and multiple persistence mechanisms. Tool and payload rotation described by Darktrace also means an investigation based only on one filename or a historic blocklist can miss related activity or misclassify it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The published analyses explain historically reported capabilities, but they do not establish whether MyKings remains active at the same scale, provide a current global infection count, or verify present-day operator attribution. Use them to understand the reported anatomy and investigative questions; use current, environment-specific intelligence for operational decisions.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.