Last seven days
- First activity
- Sep 3, 2026
- Last activity
- Sep 5, 2026
- Feed role
- C2 / Distribution
- Host form
- 2 IP / 0 hostnames
CoinMiner is a generic cryptocurrency-mining malware family name used for multiple variants that monetize compromised systems by hijacking compute resources.
Profile source: Mallory opens in a new tabCoinMiner
CoinMiner is a generic cryptocurrency-mining malware family name used for multiple variants that monetize compromised systems by hijacking compute resources. It is most commonly associated with Windows infections, though some reporting also uses the label more broadly for Linux-focused mining activity. CoinMiner infections have been observed as standalone payloads, as secondary payloads dropped by other malware, and as part of opportunistic post-compromise monetization on exposed services such as MS-SQL and Exchange servers.
On Windows, CoinMiner variants are repeatedly described as spreading laterally through Windows Management Instrumentation and, in some cases, EternalBlue-enabled propagation. Persistence has been associated with WMI Standard Event Consumer scripting. Delivery has been linked to malspam, phishing-adjacent lure chains, fake or compromised software distribution, and installation by other malware families or loaders. CoinMiner payloads have also appeared in campaigns using packers and loaders such as TrickGate, and in multi-stage botnet ecosystems such as Amadey, where mining provides immediate revenue alongside credential theft and access resale.
Operationally, CoinMiner is frequently used by financially motivated actors as a low-friction monetization step after initial access. Intrusions have shown CoinMiner deployed against internet-exposed MS-SQL servers, sometimes followed by privilege escalation and additional remote-control tooling. Other campaigns have paired CoinMiner with broader malware distribution, including Android-targeting infrastructure, or embedded mining components into destructive malware variants. Reporting also places CoinMiner among common threats observed against Linux SSH-exposed environments, although the specific family boundaries under this label vary by vendor.
Because "CoinMiner" is often used as a broad detection or family label rather than a single well-bounded codebase, capabilities can differ across variants. High-confidence common traits are cryptocurrency mining, network propagation in some Windows variants, and persistence through WMI-based mechanisms.
C2 tracking
Derp observations, rolling seven-day window
Samples
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.