VictoryGate is a Windows-based cryptomining botnet active since at least May 2019, with infections concentrated in Latin America and the vast majority observed in Peru. Its primary monetization method is unauthorized Monero mining, and the operation was assessed to have compromised at least tens of thousands of systems. Victims included both public- and private-sector organizations, including financial institutions.
VictoryGate propagates through removable USB media. On infected systems, it hides legitimate files on attached drives, replaces them with lookalike executables generated from AutoIt scripts, and when a user opens one of the decoy files it launches both the expected document or program and the malware. The malware establishes persistence by copying itself into a user profile location and creating startup mechanisms; later-stage payloads were also observed creating scheduled tasks and startup shortcuts.
The initial component is a large .NET assembly padded with junk data to hinder scanning. At runtime it unpacks an embedded payload and loads it via .NET reflection, then injects code into legitimate Windows processes using process hollowing and low-level NTAPI functions to reduce visibility and evade basic monitoring. An injected AutoIt-based agent manages command-and-control communications, monitors for newly connected USB devices to continue propagation, and can download and execute additional payloads.
A later-stage payload deploys XMRig for Monero mining by injecting it into a legitimate process. VictoryGate used a proxy-based mining architecture rather than connecting miners directly to a pool. It also included user-awareness evasion, suspending mining activity when Task Manager was opened and resuming afterward. Infected hosts commonly exhibited sustained CPU utilization in the 90% to 99% range, causing severe performance degradation and potential overheating.
Beyond cryptomining, VictoryGate functioned as a general-purpose botnet capable of receiving commands, reporting host information, maintaining keep-alives, re-establishing its installed location, and downloading further payloads. This made it a broader post-compromise risk even where mining was the main observed activity. Command-and-control infrastructure relied on dynamic DNS subdomains, and disruption of that infrastructure impaired operator control, although already infected systems could continue mining without receiving new commands.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
When executed, this file will first create a scheduled task and another shortcut in the startup folder to gain persistence for this new binary.
VictoryGate will use several undocumented NTAPI functions such as NtWriteVirtualMemory, rather than using the more common API function WriteProcessMemory, to avoid basic API-hooking detection.
It seemingly has all the files with the same names and icons that it contained before being infected. Because of this, the content will look almost identical at first glance. However, all the original files were replaced by a copy of the malware.
34 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as an example of a prior coin-mining campaign that used similar mining tools.
Botnet malware used for cryptojacking, specifically mining Monero by abusing the CPU/GPU resources of infected Windows computers.
A previously undocumented botnet primarily affecting devices in Peru, spread via removable USB devices. It replaces files on infected drives with malware copies that launch both the intended file and a malicious payload when opened. Its main observed activity is Monero cryptomining, causing sustained 90% to 99% CPU usage, and operators can update downloaded payloads to perform other malicious actions.
A previously undocumented botnet centered on an initial .NET module that communicates with C2, propagates via removable USB drives, establishes persistence, downloads and executes secondary payloads, injects code into legitimate Windows processes, and primarily monetizes infections through Monero cryptomining.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.