{
  "name": "Analysis of T-Rex CoinMiner Attacks Targeting Internet Caf\u00e9s in Korea",
  "slug": "analysis-of-t-rex-coinminer-attacks-targeting-internet-cafes-in-korea",
  "description": "A series of attacks targeting Korean Internet caf\u00e9s have been identified, focusing on systems with specific management software installed. The threat actor, active since 2022, uses Gh0st RAT for system control and ultimately installs T-Rex CoinMiner for cryptocurrency mining. The initial access method remains unknown. The attacks involve memory patching of management software and use of downloaders. The malware suite includes Gh0st RAT, its droppers, patchers, downloaders, and T-Rex CoinMiner. Unlike typical coin mining operations using XMRig for Monero, this actor employs T-Rex, likely due to the presence of high-performance GPUs in Internet caf\u00e9 PCs. The attacks have been ongoing since late 2024, prompting responses from management software manufacturers.",
  "published": "2025-06-04T18:38:53+00:00",
  "created_at": "2025-06-04T18:38:53+00:00",
  "modified_at": "2025-06-04T22:46:06+00:00",
  "created_at_opencti": "2025-06-04T18:38:53+00:00",
  "author": "",
  "confidence": null,
  "report_types": [],
  "labels": [],
  "tags": [
    "2025-06-04",
    "cryptocurrency mining",
    "gh0st rat",
    "gpu mining",
    "phoenixminer",
    "t-rex coinminer"
  ],
  "related_entities": {
    "observables": [
      {
        "id": "",
        "name": "122.199.149.129"
      },
      {
        "id": "",
        "name": "121.67.87.250"
      },
      {
        "id": "",
        "name": "115.23.126.178"
      },
      {
        "id": "",
        "name": "113.21.17.102"
      },
      {
        "id": "",
        "name": "112.217.151.10"
      },
      {
        "id": "",
        "name": "103.25.19.32"
      },
      {
        "id": "",
        "name": "121.147.158.132"
      },
      {
        "id": "",
        "name": "d172c757fe0f095054704ef5449dc2c95f98d1385cf50a28932de6c5484cc67c"
      },
      {
        "id": "",
        "name": "b46a32f1e37499aaf7a13fa3826b45bba49f268929a565c127761a40cfb84e80"
      }
    ],
    "attack_patterns": [
      {
        "id": "1e043fe4-2413-4b8e-887c-0fe45d095a24",
        "name": "T1583"
      }
    ],
    "others": [
      {
        "id": "",
        "name": "Korea, Republic of"
      }
    ]
  },
  "external_refs": [
    "https://asec.ahnlab.com/en/88245",
    "https://otx.alienvault.com/pulse/6840aeddc28c5d119100354d"
  ]
}