<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cryptojacking · Diary of a Lost Honeypot</title><link>https://blog.efespain.com/en/tags/cryptojacking/</link><description>A honeypot in some corner of the network. Every infection, a story worth telling.</description><generator>Hugo</generator><language>en</language><managingEditor>eFeSpain</managingEditor><webMaster>eFeSpain</webMaster><copyright>2026 eFeSpain</copyright><lastBuildDate>Tue, 01 Sep 2026 12:00:00 +0000</lastBuildDate><atom:link href="https://blog.efespain.com/en/tags/cryptojacking/index.xml" rel="self" type="application/rss+xml"/><item><title>Sixty-six seconds</title><link>https://blog.efespain.com/en/chapter-26/</link><pubDate>Tue, 01 Sep 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-26/</guid><description>The family from the previous chapter didn't stand still: there's a newer build going around, and I caught it from the first second. It brute-forces its way in over SSH, sizes the machine up, evicts the competition —its own older version included—, uploads sixteen megabytes in a single file and fires. All in a little over a minute. And then it walks straight into one line of fstab.</description></item><item><title>The wallet that never travels</title><link>https://blog.efespain.com/en/chapter-28/</link><pubDate>Tue, 01 Sep 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-28/</guid><description>The two previous chapters left the kit taken apart piece by piece, and one question unanswered: who it pays. I went looking. And what I found was a design that prevents it — the mining config never travels inside the critter, it gets downloaded afterwards — and scaffolding somebody had already dismantled. This is the chase, what it does plant when you let it run, and how far what I can prove about who's behind it actually goes.</description></item><item><title>The line nobody wrote</title><link>https://blog.efespain.com/en/chapter-24/</link><pubDate>Tue, 01 Sep 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-24/</guid><description>The previous chapter left a number unexplained: the backdoor was deleting a different process on every installation, and that can't be known in advance. I open the miner and the answer shows up — a template with the gap already reserved. Along the way out comes the wallet the money goes to, behind encryption that's frankly laughable.</description></item><item><title>Twenty-odd dollars a day</title><link>https://blog.efespain.com/en/chapter-25/</link><pubDate>Tue, 01 Sep 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-25/</guid><description>The teardown left me a Monero wallet and a question the binary doesn't answer: how much has this thing earned. Monero is built so no balance can be looked up — but the pool they mine against publishes per-wallet statistics, and that's an open page. What turned up when I asked: one wallet collecting since January 2021, another already running months before it showed up in any sample, about twenty-three dollars a day, and an electricity bill paid by the victims that comes to more than the operator makes.</description></item><item><title>The command that lies</title><link>https://blog.efespain.com/en/chapter-23/</link><pubDate>Tue, 01 Sep 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-23/</guid><description>I left a password sitting on a decoy and, one Sunday, something came through it three times. I neutralised what it brought; what I didn't see until later was what it left planted — a line in .bashrc that makes «top» lie and hide the very process eating the machine. A rootkit without a rootkit. And putting two frozen disks side by side turned up the detail that changes everything: the same line, with a different number.</description></item><item><title>I went back for RedTail, and RedTail already had an owner</title><link>https://blog.efespain.com/en/chapter-15/</link><pubDate>Sat, 01 Aug 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-15/</guid><description>I built a cage, ran the miner and pulled from memory the configuration I couldn't decrypt back in chapter 6. I got excited… and walked away with two things I wasn't looking for: that this family was already documented top to bottom —somewhere it never occurred to me to look— and that the piece I thought I'd decrypted was for something else.</description></item><item><title>A miner that got a bit lost</title><link>https://blog.efespain.com/en/chapter-10/</link><pubDate>Sat, 01 Aug 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-10/</guid><description>Another APK came in through the debug cable, but this one weighs fifteen times less than the last and doesn't carry a single line of native code. I opened it expecting something mediocre. What I found was a 2018 fossil still infecting phones to mine for a company that shut down seven years ago — and which today, without knowing it, warns its own victims.</description></item><item><title>The intruder who brought his own key</title><link>https://blog.efespain.com/en/chapter-5/</link><pubDate>Sat, 01 Aug 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-5/</guid><description>The previous critter kicked the door in with wget. This one walked in with an SSH key in its pocket, cleared the house of rival miners, and settled in with a professional's manners. It's RedTail, and it plays in a different league.</description></item><item><title>The miner that hides its wallet</title><link>https://blog.efespain.com/en/chapter-6/</link><pubDate>Sat, 01 Aug 2026 12:00:00 +0000</pubDate><guid>https://blog.efespain.com/en/chapter-6/</guid><description>We unpack RedTail's miner and crack it open in Ghidra hunting for the pool and the wallet. What we find is more interesting than a number: the data is in there, embedded and encrypted — and nobody has published how to crack it.</description></item></channel></rss>