A spate of illicit mining activity over the past year could be attributed to several actors that have netted them hundreds of thousands of U.S. dollars combined. These groups have used similar TTPs, including shell scripts masquerading as JPEG files with the name “logo*.jpg” that install cron jobs and download and execute miners. The 8220 Mining Group leverages Pastebin sites, Git repositories and malicious Docker images. These attacks steal CPU cycles from compromised devices to mine cryptocurrencies and bring in income for the threat actor.”]
Source: https://blog.talosintelligence.com/2018/12/cryptomining-campaigns-2018.html

