Skip to content

XMRig

XMRig is an open-source, cross-platform cryptocurrency-mining application primarily used to mine Monero and other RandomX-based currencies.

Profile source: Mallory opens in a new tab

XMRig

Family profile

XMRig is an open-source, cross-platform cryptocurrency-mining application primarily used to mine Monero and other RandomX-based currencies. Although legitimate mining software, it is frequently deployed without authorization by opportunistic cybercriminals following exploitation of exposed services, vulnerable applications, cloud and container workloads, and compromised endpoints. Observed abuse includes use on Linux, Windows, and macOS systems, often with CPU-tuning options intended to improve RandomX mining performance. Operators commonly rename or stage XMRig to resemble legitimate software, run it detached or through persistence mechanisms, remove competing miners, and configure it to connect to attacker-controlled mining pools. XMRig has appeared as a payload in campaigns targeting AI infrastructure, internet-exposed macOS Screen Sharing services, vulnerable Java applications, social-media-propagated malware infections, and trojanized software-update ecosystems.

Capabilities

  • Crypto Theft

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 22, 2026
Last activity
Aug 29, 2026
Feed role
C2 / Distribution
Host form
137 IP / 115 hostnames

Leading locations

  • US74
  • DE35
  • CN32
  • NL12
  • RU10
  • KR9
  • HK7
  • FR5
  • PL5
  • SG5
  • BR4
  • GB4

Leading providers

  • Amazon.com, Inc.23
  • Cloudflare, Inc.21
  • Amazon.com, Inc.9
  • FEMO IT SOLUTIONS LIMITED8
  • CHINA UNICOM China169 Backbone6
  • Shenzhen Tencent Computer Systems Company Limited6

Infrastructure traits

  • Hosting 188
  • Anycast 25

Samples

Recent associated samples

Reported operators

Threat actors

46 named in public reporting
TeamPCP

“Revenue came from three sources. XMRig mining paid little. A rented proxy network brought in more.”

tunnelvision

the affected victim server subsequently made a DNS query to us‐nation‐ny[.]cf... and then subsequently executed PowerShell commands enabling the threat actors to download and execute additional malicious files, including the XMRig crypto mining software.

Magic Hound

the affected victim server subsequently made a DNS query to us‐nation‐ny[.]cf... and then subsequently executed PowerShell commands enabling the threat actors to download and execute additional malicious files, including the XMRig crypto mining software.

RAGE

RAGE est un framework Python personnalisé, généré avec l’aide de l’IA, ciblant des services exposés (...) pour déployer XMRig.

Blue Mockingbird

Blue Mockingbird has executed custom-compiled XMRIG miner DLLs using rundll32.exe.

TeamTNT

The code shown below highlights how TeamTNT installed a cryptominer on the compromised pod running in the active node of the Kubernetes cluster. The module reflects how the xmrig.tgz file is downloaded and the cryptominer is installed on the compromised pod.

Kimsuky

The cryptocurrency miner XMRig has been staged in the past on a command and control (C&C) server by TA427, but it was never confirmed if actors deployed it in the wild.

Rocke

Although Pro-Ocean attempts to disguise itself as benign, it packs an XMRig miner, which is notorious for its use in cryptojacking operations.

Freak

In the latest code downloaded (January 12, 2021), it seems that the malware tries to exploit the vulnerabilities to install the Xmrig from the server hxxp://gxbrowser[.]net.

Sysrv-Hello Botnet

IronNet observed what appeared to be a number of different botnets, in some cases pushing the same shell script but always ultimately leading to a XMRig coinminer.

TA542

On September 16, XMRig, the most common Monero (XMR) miner, was installed by Emotet using command 2 which is just for loading modules.

Cinnamon Tempest

Case 1 - XMRig ... Xmrig.exe is part of XMRig open-source CPU/GPU cryptocurrency mining software ... The downloaded payload is XMRig miner.

Dark Seoul

Exploitation of the vulnerability in VMware Horizon allowed the attackers to install the XMRIG cryptocurrency miner to a system.

Haskers Gang

In many cases, this includes the RedLine Stealer and an XMRig-based cryptocurrency mining malware that is internally referred to as "ZingoMiner."

Night Sky

Case 1 - XMRig ... Xmrig.exe is part of XMRig open-source CPU/GPU cryptocurrency mining software ... The downloaded payload is XMRig miner.

Tor2Mine

During the course of our research, we also discovered evidence suggesting that the Tor2Mine actors are deploying additional malware in tandem with XMRig during their operations to harvest credentials and steal more money.

Kinsing

We observed that the payload itself illicitly mined Monero using XMRig, an open-source and multiplatform Monero miner.

APT41

We were able to obtain and decrypt the .mui files loaded by Win64/Winnti.BN. They were actually XMRig executables, again packed using the same custom packer as the one used to pack the 1st stage of compromised games as well as the PortReuse backdoor.

Outlaw

Database server misused to mine Monero via the coinminer file xmrig-2.5.3-xenial-amd64.tar ... The corresponding wallet address was found with 1.161 XMR at the time of writing.

z0Miner

Imperva security researchers were able to identify attackers’ attempts to exploit this vulnerability in order to install and run the XMRig cryptocurrency miner on affected Confluence servers running on Windows and Linux systems.

APT-Q-27

经过分析,该样本确认为 XMRig 挖矿木马,木马自带配置文件并且支持通过硬编码URL远程更新配置信息。

金眼狗

经过分析,该样本确认为 XMRig 挖矿木马,木马自带配置文件并且支持通过硬编码URL远程更新配置信息。

GREYVIBE

The deployment of an XMRig miner payload on a small number of LegionRelay-infected machines.

Larva-26009

the AhnLab SEcurity intelligence Center (ASEC) identified an instance in which the Larva-26009 threat actor installed the XMRig CoinMiner.

Operation STANDOFF

Il dépose entre 40 et 50 exécutables ... et installe simultanément plusieurs familles de malwares : XMRig v6.2.2 (minage Monero, pool pool.supportxmr.com:3333 )

Prvaz12mars

The packages copied legitimate Ruby libraries and altered their entry-point files to launch mining code... Download URL raw.githubusercontent.com/xmrig/xmrig/v6.22.2/xmrig-6.22.2-linux-static-x64.tar.gz Miner archive download location

monib110

The packages copied legitimate Ruby libraries and altered their entry-point files to launch mining code... Download URL raw.githubusercontent.com/xmrig/xmrig/v6.22.2/xmrig-6.22.2-linux-static-x64.tar.gz Miner archive download location

RedTail

Криптоджекинг (T1496, Resource Hijacking). Развёртывание XMRig - самый частый сценарий.

Rare Werewolf

Rezet (Rare Werewolf) ... развёртывание XMRig-майнера

Rezet

Rezet (Rare Werewolf) ... развёртывание XMRig-майнера

Librarian Ghouls

The observed tactics, targeting, and tradecraft closely align with the Rare Werewolf (Librarian Ghouls) threat actor, although no XMRig cryptomining activity was observed in this sample.

8220 Gang

If the CVE-2022-26134 vulnerability attack succeeds, the following PowerShell command downloads and executes additional PowerShell scripts and ultimately installs XMRig CoinMiner.

TWIZT

xmr.exe (7MB) -- XMRig Miner Binary (PE32+ x64)

xssNew

Cryptominer Deployment The platform deploys a custom cryptomining agent to compromised hosts... Architecture Component Detail Agent Binary multimmm-user (custom Go binary) Miner XMRig (Monero)

UAC-0247

In one case, investigators detected the use of XMRig, a legitimate cryptocurrency mining tool, suggesting attackers may have used victims’ computing resources to generate digital currency.

REF1695

...as well as a custom .NET-based XMRig loader...

APT4

XMRig is an open-source Monero mining application frequently abused by cybercriminals. TeamPCP deploys XMRig on compromised hosts to mine Monero using the victim’s CPU resources without authorization.

Pacha Group

XMRig is an open-source Monero mining application frequently abused by cybercriminals. TeamPCP deploys XMRig on compromised hosts to mine Monero using the victim’s CPU resources without authorization.

CRYSTALRAY

CRYSTALRAY has two associated cryptominers... (IoCs include xmrig_arm64 and xmrig_freebsd binaries).

DreamBus

DreamBus botnet was observed leveraging an CVE-2023-33246 exploit to drop XMRig Monero miners on vulnerable servers.

UAC-0006

C:\Users\Public\ProgramData\xmrig.exe та (tcp)://xmr.2miners[.]com:2222

IronErn440

It uses XMRig to mine for Monero and makes sure that it uses only 60% of the processing power to evade immediate detection.

Lemon Duck

“CoinMiner XMRig, a CoinMiner that mines the Monero cryptocurrency, was the one the most used in the attacks.”

Contagious Interview

"TsunamiHardener... sets up... Microsoft Defender exclusions for TsunamiClient and the XMRig miner"

Wagner

The code references XMRig, an open-source tool commonly used to mine Monero (XMR), and several Rusich-linked addresses have received funds from mining pools.

Task Force Rusich

The code references XMRig, an open-source tool commonly used to mine Monero (XMR), and several Rusich-linked addresses have received funds from mining pools.

Exploited software

Vulnerabilities linked to XMRig

64 CVEs
CVE-2026-42271 Authenticated Command Injection in BerriAI LiteLLM MCP Test Endpoints CVE-2026-65400 Authentication Bypass in macOS Screen Sharing CVE-2026-49869 Kestra OSS Authentication Bypass and Remote Code Execution CVE-2026-48710 BadHost: Starlette Host Header Path-Based Authorization Bypass CVE-2021-44228 Log4Shell CVE-2019-19781 Shitrix: Citrix ADC and Gateway Directory Traversal CVE-2025-55182 React2Shell CVE-2026-20128 Information Disclosure in Cisco Catalyst SD-WAN Manager Data Collection Agent CVE-2026-20133 Information Disclosure in Cisco Catalyst SD-WAN Manager CVE-2026-20122 Arbitrary File Overwrite in Cisco Catalyst SD-WAN Manager API CVE-2024-23897 Jenkins CLI Arbitrary File Read CVE-2020-14882 Oracle WebLogic Server Console Unauthenticated Remote Code Execution CVE-2025-32432 Pre-authentication RCE in Craft CMS image transformation CVE-2021-26084 Atlassian Confluence Server and Data Center OGNL Injection RCE CVE-2020-28188 TerraMaster TOS makecvs.php Event Parameter Command Injection CVE-2021-45046 Apache Log4j Thread Context Lookup Denial of Service CVE-2021-3007 Laminas/Zend Framework Stream Response Insecure Deserialization CVE-2020-11652 Directory Traversal in SaltStack Salt ClearFuncs CVE-2020-7961 Java Deserialization RCE in Liferay Portal JSONWS CVE-2020-11651 Authentication Bypass and RCE in SaltStack Salt CVE-2020-35665 Unauthenticated OS Command Injection in TerraMaster TOS CSV Creation CVE-2017-11610 Supervisor XML-RPC Server Authenticated Remote Code Execution CVE-2020-5902 F5 BIG-IP TMUI Directory Traversal Remote Code Execution CVE-2021-26085 Pre-Authorization Arbitrary File Read in Atlassian Confluence Server /s/ Endpoint CVE-2018-7600 Drupalgeddon2 CVE-2020-2507 Command Injection in QNAP Helpdesk (QTS) CVE-2021-40438 Apache HTTP Server mod_proxy Server-Side Request Forgery CVE-2021-21973 VMware vCenter Server vSphere Client Plugin SSRF CVE-2021-22986 F5 BIG-IP and BIG-IQ iControl REST Unauthenticated Remote Command Execution CVE-2021-21985 Remote Code Execution in VMware vCenter Server vSphere Client VSAN Health Check Plug-in CVE-2021-22005 Unauthenticated Arbitrary File Upload RCE in VMware vCenter Server Analytics Service CVE-2020-2506 Improper Access Control in QNAP Helpdesk <3.0.3 CVE-2021-41773 Path Traversal and Possible RCE in Apache HTTP Server 2.4.49 CVE-2020-14750 Oracle WebLogic Server Console path traversal patch bypass leading to unauthenticated RCE CVE-2020-14883 Oracle WebLogic Server Console Authentication Bypass / RCE Chain CVE-2021-21972 Unauthenticated RCE in VMware vCenter Server vROPS Plugin CVE-2021-42013 Path Traversal and Possible RCE in Apache HTTP Server 2.4.49/2.4.50 CVE-2019-1003000 Jenkins Script Security Plugin Groovy Sandbox Bypass RCE CVE-2016-3088 Remote File Upload and RCE in Apache ActiveMQ Fileserver CVE-2015-1427 Elasticsearch Groovy Sandbox Bypass RCE CVE-2018-1000861 Jenkins Stapler Web Framework Remote Code Execution CVE-2023-33246 Remote Command Execution in Apache RocketMQ Update Configuration Function CVE-2026-41940 cPanel & WHM Login Flow Authentication Bypass CVE-2026-54420 LiteSpeed cPanel Plugin Symlink-Following Privilege Escalation CVE-2021-22205 Unauthenticated Remote Command Execution in GitLab CE/EE via ExifTool CVE-2024-27198 Authentication Bypass in JetBrains TeamCity On-Premises CVE-2024-4577 PHP-CGI Argument Injection RCE on Windows CVE-2026-33017 Unauthenticated RCE in Langflow Public Flow Build Endpoint CVE-2025-31324 Unauthenticated Arbitrary File Upload RCE in SAP NetWeaver Visual Composer Metadata Uploader CVE-2021-41285 Privilege Escalation in Ballistix MOD Utility MODAPI.sys Driver CVE-2020-14979 Local Privilege Escalation in EVGA Precision X1 WinRing0 Driver CVE-2022-26134 Atlassian Confluence OGNL Injection Remote Code Execution CVE-2024-0012 Authentication Bypass in Palo Alto Networks PAN-OS Management Web Interface CVE-2024-9474 Privilege Escalation in Palo Alto Networks PAN-OS Web Management Interface CVE-2022-22954 Server-Side Template Injection RCE in VMware Workspace ONE Access and Identity Manager CVE-2023-38646 Pre-auth RCE in Metabase setup validation CVE-2023-48022 Unauthenticated RCE in Anyscale Ray Job Submission API CVE-2026-20182 Authentication Bypass in Cisco Catalyst SD-WAN Peering Authentication CVE-2024-3400 PAN-OS GlobalProtect Command Injection CVE-2025-29927 Next.js Middleware Authorization Bypass CVE-2020-35489 Unrestricted File Upload in Contact Form 7 for WordPress CVE-2024-23692 Rejetto HTTP File Server Template Injection RCE CVE-2025-24893 Unauthenticated RCE in XWiki SolrSearch CVE-2021-24284 Unauthenticated Arbitrary File Upload in Kaswara Modern VC Addons WordPress Plugin

MITRE ATT&CK

XMRig in ATT&CK

84 distinct techniques

Techniques

84 techniques
T1496 Resource Hijacking T1027 Obfuscated Files or Information T1059 Command and Scripting Interpreter T1036 Masquerading T1105 Ingress Tool Transfer T1070.004 File Deletion T1564.001 Hidden Files and Directories T1562.001 Disable or Modify Tools T1204.002 Malicious File T1543.001 Launch Agent T1071.001 Web Protocols T1059.002 AppleScript T1102.001 Dead Drop Resolver T1059.004 Unix Shell T1613 Container and Resource Discovery T1049 System Network Connections Discovery T1610 Deploy Container T1059.001 PowerShell T1190 Exploit Public-Facing Application T1057 Process Discovery T1053.003 Cron T1095 Non-Application Layer Protocol T1036.005 Match Legitimate Resource Name or Location T1222.002 Linux and Mac File and Directory Permissions Modification T1518 Software Discovery T1204 User Execution T1195 Supply Chain Compromise T1203 Exploitation for Client Execution T1006 Direct Volume Access T1195.001 Compromise Software Dependencies and Development Tools T1553.001 Gatekeeper Bypass T1566 Phishing T1053.005 Scheduled Task T1489 Service Stop T1562 Impair Defenses T1055.012 Process Hollowing T1106 Native API T1497 Virtualization/Sandbox Evasion T1055 Process Injection T1543 Create or Modify System Process T1071 Application Layer Protocol T1059.003 Windows Command Shell T1543.003 Windows Service T1218.010 Regsvr32 T1195.002 Compromise Software Supply Chain T1070 Indicator Removal T1497.001 System Checks T1570 Lateral Tool Transfer T1071.004 DNS T1027.002 Software Packing T1053 Scheduled Task/Job T1562.004 Disable or Modify System Firewall T1090.003 Multi-hop Proxy T1547.001 Registry Run Keys / Startup Folder T1497.002 User Activity Based Checks T1218 System Binary Proxy Execution T1556 Modify Authentication Process T1222 File and Directory Permissions Modification T1132 Data Encoding T1078 Valid Accounts T1218.005 Mshta T1083 File and Directory Discovery T1547.009 Shortcut Modification T1091 Replication Through Removable Media T1588.001 Malware T1082 System Information Discovery T1021.004 SSH T1574.006 Dynamic Linker Hijacking T1496.001 Compute Hijacking T1046 Network Service Discovery T1569.002 Service Execution T1620 Reflective Code Loading T1036.004 Masquerade Task or Service T1110 Brute Force T1014 Rootkit T1133 External Remote Services T1059.006 Python T1027.003 Steganography T1112 Modify Registry T1189 Drive-by Compromise T1564.010 Process Argument Spoofing T1074.001 Local Data Staging T1102 Web Service T1499 Endpoint Denial of Service

Reporting

Research mentioning XMRig

Aug 26
Malware News

When AI infrastructure becomes the target: Securing gateways and control points - Malware News - Malware Analysis, News and Indicators

Microsoft observed intrusions targeting exposed LiteLLM, RAGFlow, and Kestra AI control-plane workloads to obtain credentials, establish persistence, access downstream data, and deploy cryptocurrency-mining tools. In the LiteLLM case, attackers likely exploited an exposed gateway, harvested runtime and PostgreSQL secrets, deployed XMRig-like tooling, and persisted through SSH keys, cron modifications, hidden files, and immutable file attributes. In a RAGFlow environment, attackers conducted SSRF-style reconnaissance and modified the application to persistently intercept newly configured LLM-provider credentials; Microsoft did not confirm the code-execution vulnerability used. A Kestra intrusion was assessed as likely exploiting CVE-2026-49869 to bypass authentication, run malicious workflows, access Docker container environments, deploy XMRig, and collect data through Kestra's key-value interface. Microsoft advised treating AI gateways, retrieval platforms, and workflow orchestrators as critical control-plane infrastructure because they centralize privileged execution and high-value secrets.

Aug 26
Microsoft General

When AI infrastructure becomes the target: Securing gateways and control points | Microsoft Security Blog

Aug 20
Netbytesec

Anatomy of a macOS ClickFix Crimekit that Weaponises EtherHiding

Researchers reported multiple social-engineering campaigns targeting macOS users with fake CAPTCHA and ClickFix lures that trick victims into copying and pasting malicious commands into Terminal, shifting execution to the user and bypassing traditional app-download protections. One campaign delivered Atomic macOS Stealer (AMOS) through trojanized cracked applications and malicious Terminal instructions, stealing credentials, browser data, cryptocurrency wallets, Telegram data, VPN profiles, keychain contents, Apple Notes, and files from common user folders before compressing and exfiltrating them over HTTP/HTTPS. Trend Micro separately documented multistage fake CAPTCHA attacks that also led to infostealers and remote-access trojans, underscoring the broader use of human-verification themes to launch malware chains. A separate July 2026 macOS campaign used a fake TrustKey verification page on Cloudflare Pages, a Cloudflare Worker, and an AppleScript-based loader to install a persistent backdoor named bmodule via LaunchAgent persistence. The malware dynamically resolved live command-and-control infrastructure from a Polygon smart contract using an EtherHiding technique, then fingerprinted hosts, phished macOS login passwords, and fetched tasks to deploy AMOS variants, an interactive shell, or an XMRig cryptominer. Apple said macOS Sequoia has updated runtime protections, while incident reporting shows Terminal-based social-engineering chains remain effective because they rely on users to execute the malicious commands directly.

Aug 18
Trendai Security

An MDR Analysis of the AMOS Stealer Campaign Targeting macOS via Cracked Apps | TrendAI (US)

Aug 15
Github Web

GitHub - tjnel/certgraveyard_yara: Automated YARA rule generation from the Cert Central compromised certificate database. · GitHub

A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.

Aug 3
Securelist

Incident response statistics and cases at educational institutions in Brazil | Securelist

Brazilian educational institutions faced a sustained wave of cyber incidents in incident-response cases reviewed from January 2025 through June 2026, with attackers most often gaining access through valid accounts, exploitation of public-facing applications, insider activity, and weak patch management. High-severity cases were dominated by ransomware, particularly DragonForce and LockBit 3, and private institutions were more frequently affected than public ones. Investigators also found that outdated and unpatched systems, including Windows 10 deployments kept past end of support and unpatched Windows Server 2016 hosts, materially increased exposure. Representative intrusions showed attackers relying on common but effective techniques rather than novel tradecraft. One LockBit case involved a custom deployment built from the leaked builder and spread with PsExec, aligning with the well-documented abuse of Windows service execution for lateral movement and payload launch. Another DragonForce intrusion used AnyDesk and log wiping to maintain access and hinder response, while a separate insider case involved a Python keylogger installed on a shared machine to capture credentials. The findings underscore the need for MFA, least privilege, removal of shared accounts, tighter control of remote-access tools, stronger backups, centralized logging, longer EDR retention, and faster patching.

Jul 31
Sysdig

Malware analysis: Hands-On Shellbot malware | Sysdig

Researchers linked multiple Linux intrusions to a Romanian-speaking threat cluster that brute-forced weak SSH credentials, compromised servers and network devices at scale, and deployed a Perl-based Shellbot with IRC command-and-control. Trend Micro found infrastructure capable of generating target lists covering roughly 80 million IP addresses, logs indicating more than 65,000 potentially compromised hosts, and tooling including the Haiduc SSH brute-forcer, process-masquerading utility Faker, privilege-escalation exploits such as CVE-2017-16995 and Dirty Cow variants, and high-availability C2 built with CARP. Bitdefender separately tied a likely Romanian group to Linux-focused scanning, SHC-obfuscated loaders, Discord webhook reporting, a customized Perl IRC bot, and a Golang SSH bruteforcer offered in a SaaS-like model, with monetization centered on Monero mining via customized XMRig payloads. Additional reporting showed the campaign’s tradecraft remained active across traditional servers and cloud-native environments. JPCERT/CC documented attackers using stolen SSH access to move laterally, install XMRig, hide mining with XHide, tamper with logs, and continue scanning for new SSH targets, while Sysdig observed Shellbot compromise a Tomcat container through brute-forced default credentials, download multi-architecture payloads, establish persistence, erase traces, and receive commands for file transfer, port scanning, data exfiltration, and DDoS attacks. Together, the reports describe a long-running Linux-focused operation that blends brute-force access, worm-like propagation, cryptojacking, and botnet functionality across exposed infrastructure.

Jul 31
Sysdig

Threat news: TeamTNT stealing credentials using EC2 Instance Metadata | Sysdig

TeamTNT continued to evolve from a Linux-focused cryptojacking group into a broad cloud threat actor targeting exposed Redis, Docker, Kubernetes, Jupyter, Hadoop, PostgreSQL, Tomcat, Nginx, SSH, and other internet-facing services. Researchers tied the group to worm-like campaigns that rapidly scanned for vulnerable hosts, deployed XMRig miners, dropped Tsunami-based IRC bots including DDoS-capable variants, and used malicious container images on Docker Hub to spread payloads at scale. One TeamTNT-linked Docker Hub account reportedly served images pulled more than 150,000 times, while later campaigns showed the group abusing public registries, compromised accounts, and cloud-native tooling to infect newly exposed systems and report them back to command-and-control infrastructure. Across these operations, TeamTNT consistently paired monetization with aggressive credential theft and stealth. Investigations found the group harvesting AWS, Azure, GCP, Kubernetes, Git, NPM, Grafana, database, and storage secrets; stealing SSH keys and host data; and using tools such as Weave Scope, Peirates, BotB, MimiPenguin, Mimipy, tmate, and Gsocket to expand access and persistence. Analysts also documented detection evasion through log wiping, process hiding, LD_PRELOAD userland rootkits, the Diamorphine kernel rootkit, privileged containers with restart policies, and even disabling runc to lock out rival attackers, underscoring TeamTNT’s shift from opportunistic mining to sustained compromise of cloud and container environments.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.