Skip to content

CoinMiner

CoinMiner is a generic cryptocurrency-mining malware family name used for multiple variants that monetize compromised systems by hijacking compute resources.

Profile source: Mallory opens in a new tab

CoinMiner

Family profile

CoinMiner is a generic cryptocurrency-mining malware family name used for multiple variants that monetize compromised systems by hijacking compute resources. It is most commonly associated with Windows infections, though some reporting also uses the label more broadly for Linux-focused mining activity. CoinMiner infections have been observed as standalone payloads, as secondary payloads dropped by other malware, and as part of opportunistic post-compromise monetization on exposed services such as MS-SQL and Exchange servers.

On Windows, CoinMiner variants are repeatedly described as spreading laterally through Windows Management Instrumentation and, in some cases, EternalBlue-enabled propagation. Persistence has been associated with WMI Standard Event Consumer scripting. Delivery has been linked to malspam, phishing-adjacent lure chains, fake or compromised software distribution, and installation by other malware families or loaders. CoinMiner payloads have also appeared in campaigns using packers and loaders such as TrickGate, and in multi-stage botnet ecosystems such as Amadey, where mining provides immediate revenue alongside credential theft and access resale.

Operationally, CoinMiner is frequently used by financially motivated actors as a low-friction monetization step after initial access. Intrusions have shown CoinMiner deployed against internet-exposed MS-SQL servers, sometimes followed by privilege escalation and additional remote-control tooling. Other campaigns have paired CoinMiner with broader malware distribution, including Android-targeting infrastructure, or embedded mining components into destructive malware variants. Reporting also places CoinMiner among common threats observed against Linux SSH-exposed environments, although the specific family boundaries under this label vary by vendor.

Because "CoinMiner" is often used as a broad detection or family label rather than a single well-bounded codebase, capabilities can differ across variants. High-confidence common traits are cryptocurrency mining, network propagation in some Windows variants, and persistence through WMI-based mechanisms.

Capabilities

  • Lateral Movement
  • Persistence

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 3, 2026
Last activity
Sep 5, 2026
Feed role
C2 / Distribution
Host form
2 IP / 0 hostnames

Leading locations

  • BG1
  • LV1

Leading providers

  • AS56971 Cloud1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Exploited software

Vulnerabilities linked to CoinMiner

1 CVEs

MITRE ATT&CK

CoinMiner in ATT&CK

11 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.