Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In late 2017, AlienVault identified a malicious installer that secretly deployed xmrig, an open-source Monero miner, on victims’ computers. Its configuration pointed mining proceeds to a server associated with Kim Il Sung University (KSU) in Pyongyang. The server did not appear to work, however, and AlienVault warned that the North Korea reference could have been a false flag. The evidence supports a suspected connection—not definitive attribution to North Korea, KSU, or Lazarus.

What the malware did

The sample was an installer that appeared to provide software but also placed xmrig on the system. Xmrig used the victim’s CPU to mine Monero without informed consent. The operator therefore obtained cryptocurrency by diverting computing capacity from end users and servers rather than by asking them to run a miner.

AlienVault said the installer appeared to have been created before Christmas 2017. Dark Reading published the findings on January 8, 2018.

How the mining operation was configured

The payload: xmrig

Xmrig is open-source mining software designed for Monero. In this case, it was bundled into the malicious installer and run covertly after installation. The report does not establish a specific victim count, persistence method, or delivery campaign beyond the installer itself.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The KSU destination

The sample’s configuration named a server associated with Kim Il Sung University in Pyongyang as the destination for mined coins. AlienVault found that the link did not appear to function, so there is no evidence that KSU actually received the proceeds. A deliberately planted university reference could have been intended to mislead investigators or create a political attribution trail.

Why the attacker used Monero

Monero’s mining algorithm could run on ordinary personal computers and servers, making it practical for malware that steals CPU cycles from a broad range of systems. AlienVault researcher Chris Doman described Monero as both more anonymous and more profitable for malware mining than many alternatives.

Doman also noted that rising cryptocurrency prices increase the incentive to infect other people’s devices. AlienVault framed cryptocurrency as a possible financial lifeline for a country facing sanctions and said North Korean universities had shown interest in the technology. Those observations explain the suspected motive, but they do not identify the operator of this particular sample.

Does this prove North Korea or Lazarus was responsible?

No. AlienVault said the sample was consistent with earlier North Korea-linked activity, but the available evidence did not establish attribution with complete certainty. The nonfunctional KSU destination is the central weakness: it could reflect an abandoned operation, a broken configuration, or a false flag.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The report placed the sample in a broader set of cryptocurrency activity associated with North Korean-linked groups:

  • An Andariel operation reportedly mined Monero on a hijacked South Korean organization’s server.
  • Lazarus had reportedly used compromised networks to mine Monero while conducting attacks against Bitcoin exchanges.

Those incidents provide context, not proof that the installer described here belonged to Lazarus, Andariel, or any particular North Korean agency. A code reference to KSU is an attribution clue, not independent confirmation of who wrote or operated the malware.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How much can cryptojacking botnets earn?

Contemporary estimates showed why attackers were willing to distribute mining malware. The figures below come from the incidents and assessments cited in the 2017–2018 reporting; they are not a guaranteed return for every botnet.

Source or incident Scale or measure Reported result Qualification
IBM, 2017 CPU-mining attacks against IBM customers Six-fold increase Increase measured between January and July 2017
Kaspersky Lab, 2017 Mining botnet of about 4,000 computers Up to $30,000 per month Estimate; monthly figure varies with coin price, hardware and uptime
Kaspersky Lab, 2017 Mining botnet of about 5,000 computers Up to $200,000 per month Estimate; not a reported payout from the KSU-linked sample
Andariel incident reported by Bloomberg and summarized by Dark Reading, 2018 Hijacked South Korean organization’s server About 70 Monero coins Separate incident cited as related activity

These numbers are best understood as upper-end estimates or incident-specific totals. They depend on the number and speed of infected processors, how long the malware remains active, electricity and hosting costs, the mining algorithm, and cryptocurrency prices.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Timeline of the KSU-linked sample

  1. Before Christmas 2017: The malicious installer appears to have been created.
  2. Late 2017: The installer deployed xmrig and configured it to mine Monero toward a KSU-associated server.
  3. January 8, 2018: Dark Reading published AlienVault’s analysis.
  4. During analysis: The configured destination did not appear to work, leaving the suspected North Korea connection unconfirmed.

What makes this case significant

  • It was resource theft: The malware monetized victims’ processors instead of stealing coins already held in a wallet.
  • It used commodity software: Xmrig was open-source, so the unusual part was the covert delivery and destination configuration, not a proprietary mining engine.
  • The attribution clue was unusually explicit: Naming a Pyongyang university made the sample stand out, while also creating a potential false-flag risk.
  • It fit a growing trend: IBM’s six-fold increase and Kaspersky’s botnet estimates illustrated the expanding financial incentive for CPU-mining attacks in 2017.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.