Last seven days
- First activity
- Sep 19, 2026
- Last activity
- Sep 26, 2026
- Feed role
- C2 / Distribution
- Host form
- 7 IP / 0 hostnames
CoinMiner is a generic cryptocurrency-mining malware family name used for multiple variants that monetize compromised systems by hijacking compute resources.
Profile source: Mallory opens in a new tabCoinMiner
CoinMiner is a generic cryptocurrency-mining malware family name used for multiple variants that monetize compromised systems by hijacking compute resources. It is most commonly associated with Windows infections, though some reporting also uses the label more broadly for Linux-focused mining activity. CoinMiner infections have been observed as standalone payloads, as secondary payloads dropped by other malware, and as part of opportunistic post-compromise monetization on exposed services such as MS-SQL and Exchange servers.
On Windows, CoinMiner variants are repeatedly described as spreading laterally through Windows Management Instrumentation and, in some cases, EternalBlue-enabled propagation. Persistence has been associated with WMI Standard Event Consumer scripting. Delivery has been linked to malspam, phishing-adjacent lure chains, fake or compromised software distribution, and installation by other malware families or loaders. CoinMiner payloads have also appeared in campaigns using packers and loaders such as TrickGate, and in multi-stage botnet ecosystems such as Amadey, where mining provides immediate revenue alongside credential theft and access resale.
Operationally, CoinMiner is frequently used by financially motivated actors as a low-friction monetization step after initial access. Intrusions have shown CoinMiner deployed against internet-exposed MS-SQL servers, sometimes followed by privilege escalation and additional remote-control tooling. Other campaigns have paired CoinMiner with broader malware distribution, including Android-targeting infrastructure, or embedded mining components into destructive malware variants. Reporting also places CoinMiner among common threats observed against Linux SSH-exposed environments, although the specific family boundaries under this label vary by vendor.
Because "CoinMiner" is often used as a broad detection or family label rather than a single well-bounded codebase, capabilities can differ across variants. High-confidence common traits are cryptocurrency mining, network propagation in some Windows variants, and persistence through WMI-based mechanisms.
C2 tracking
Derp observations, rolling seven-day window
Samples
30daba44a4a25ff5750508613f897057a55337458f19b562e2ed1172c77e626b 52ec3ba075a507e62bb6e3272fb13b30a8ddc0f62c4ea194311d558b338eb5ed 7126b9932dc0cdfe751340edfa7c4a14b69262eb1afd0530e6d1fdb2e25986dd 73ddf0df4e9e3866511ef9eae421b11615b81491d0db1d4a7ed19441e368ecef b914abc696286a639a847d2e3a4a36ff682f30a87b08c4ffc61f2e0cf5e7ec5f 164bb0a7f2740ed54c234ddef21d1290343ac7c59e61c981d2c19009ef3512d5 2bc90e100d5bf27581dbe8a60ae95eb2c451c39d1d7862a276dd556b1d442ec8 3cfd3c6512de02c73f4a4ce14d9f600fab07f2f7115b88653f5dba49c3e7da98 b5e0708d7c6d694b4701763be412aa40bd9e3007bbbde45e30217ee2018a9753 d0eadbe16af91847350fb4b19a393caf69d67b190c82248fbb7ec5b827b6634c Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.