In late 2017, AlienVault identified a malicious installer that secretly deployed xmrig, an open-source Monero miner, on victims’ computers. Its configuration pointed mining proceeds to a server associated with Kim Il Sung University (KSU) in Pyongyang. The server did not appear to work, however, and AlienVault warned that the North Korea reference could have been a false flag. The evidence supports a suspected connection—not definitive attribution to North Korea, KSU, or Lazarus.
What the malware did
The sample was an installer that appeared to provide software but also placed xmrig on the system. Xmrig used the victim’s CPU to mine Monero without informed consent. The operator therefore obtained cryptocurrency by diverting computing capacity from end users and servers rather than by asking them to run a miner.
AlienVault said the installer appeared to have been created before Christmas 2017. Dark Reading published the findings on January 8, 2018.
How the mining operation was configured
The payload: xmrig
Xmrig is open-source mining software designed for Monero. In this case, it was bundled into the malicious installer and run covertly after installation. The report does not establish a specific victim count, persistence method, or delivery campaign beyond the installer itself.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware match#1 Best Overall
The KSU destination
The sample’s configuration named a server associated with Kim Il Sung University in Pyongyang as the destination for mined coins. AlienVault found that the link did not appear to function, so there is no evidence that KSU actually received the proceeds. A deliberately planted university reference could have been intended to mislead investigators or create a political attribution trail.
Why the attacker used Monero
Monero’s mining algorithm could run on ordinary personal computers and servers, making it practical for malware that steals CPU cycles from a broad range of systems. AlienVault researcher Chris Doman described Monero as both more anonymous and more profitable for malware mining than many alternatives.
Rank #2
Doman also noted that rising cryptocurrency prices increase the incentive to infect other people’s devices. AlienVault framed cryptocurrency as a possible financial lifeline for a country facing sanctions and said North Korean universities had shown interest in the technology. Those observations explain the suspected motive, but they do not identify the operator of this particular sample.
Does this prove North Korea or Lazarus was responsible?
No. AlienVault said the sample was consistent with earlier North Korea-linked activity, but the available evidence did not establish attribution with complete certainty. The nonfunctional KSU destination is the central weakness: it could reflect an abandoned operation, a broken configuration, or a false flag.
The report placed the sample in a broader set of cryptocurrency activity associated with North Korean-linked groups:
- An Andariel operation reportedly mined Monero on a hijacked South Korean organization’s server.
- Lazarus had reportedly used compromised networks to mine Monero while conducting attacks against Bitcoin exchanges.
Those incidents provide context, not proof that the installer described here belonged to Lazarus, Andariel, or any particular North Korean agency. A code reference to KSU is an attribution clue, not independent confirmation of who wrote or operated the malware.
Rank #4
How much can cryptojacking botnets earn?
Contemporary estimates showed why attackers were willing to distribute mining malware. The figures below come from the incidents and assessments cited in the 2017–2018 reporting; they are not a guaranteed return for every botnet.
| Source or incident | Scale or measure | Reported result | Qualification |
|---|---|---|---|
| IBM, 2017 | CPU-mining attacks against IBM customers | Six-fold increase | Increase measured between January and July 2017 |
| Kaspersky Lab, 2017 | Mining botnet of about 4,000 computers | Up to $30,000 per month | Estimate; monthly figure varies with coin price, hardware and uptime |
| Kaspersky Lab, 2017 | Mining botnet of about 5,000 computers | Up to $200,000 per month | Estimate; not a reported payout from the KSU-linked sample |
| Andariel incident reported by Bloomberg and summarized by Dark Reading, 2018 | Hijacked South Korean organization’s server | About 70 Monero coins | Separate incident cited as related activity |
These numbers are best understood as upper-end estimates or incident-specific totals. They depend on the number and speed of infected processors, how long the malware remains active, electricity and hosting costs, the mining algorithm, and cryptocurrency prices.
Quick Recap
Timeline of the KSU-linked sample
- Before Christmas 2017: The malicious installer appears to have been created.
- Late 2017: The installer deployed xmrig and configured it to mine Monero toward a KSU-associated server.
- January 8, 2018: Dark Reading published AlienVault’s analysis.
- During analysis: The configured destination did not appear to work, leaving the suspected North Korea connection unconfirmed.
What makes this case significant
- It was resource theft: The malware monetized victims’ processors instead of stealing coins already held in a wallet.
- It used commodity software: Xmrig was open-source, so the unusual part was the covert delivery and destination configuration, not a proprietary mining engine.
- The attribution clue was unusually explicit: Naming a Pyongyang university made the sample stand out, while also creating a potential false-flag risk.
- It fit a growing trend: IBM’s six-fold increase and Kaspersky’s botnet estimates illustrated the expanding financial incentive for CPU-mining attacks in 2017.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

