Pacha Group — APT Profile

Pacha Group is the label Intezer applied to a cryptojacking operation that monetises compromised Linux servers, brought to light after its Antd miner appeared in the wild on 18 September 2018. Intezer's February 2019 technical analysis described follow-on campaigns assembled from a broad component set that security products were largely failing to flag, and named the newly identified strains Linux.GreedyAntd. Intezer researcher Ignacio Sanmillan characterised several of the group's implementation choices as unconventional, with an element of sophistication to them, and assessed the operators to be of Chinese origin. A follow-up Intezer report in May 2019 placed Pacha Group in direct competition with the Rocke Group for mining footholds on cloud infrastructure, one of the clearer public examples of rival cryptojacking crews contesting the same hosts. Malpedia records no vendor reporting on the group after that May 2019 analysis.

Tools & malware

Vendor research

Read the full analysis on IntelFusions