Last seven days
- First activity
- Jul 14, 2026
- Last activity
- Jul 21, 2026
- Feed role
- C2 / Distribution
- Host form
- 37 IP / 31 hostnames
XMRig is an open-source cryptocurrency mining program primarily used to mine Monero and other RandomX or CryptoNight-family coins.
Profile source: Mallory opens in a new tabXMRig
XMRig is an open-source cryptocurrency mining program primarily used to mine Monero and other RandomX or CryptoNight-family coins. Although legitimate in benign mining contexts, it is widely abused by threat actors as a cryptomining payload after host compromise. Intrusions involving XMRig commonly follow exploitation of internet-facing services, brute-force or credential-based access to Linux SSH servers, SQL injection against web applications, supply-chain compromise, downloader-based malware chains, and malvertising campaigns that bundle XMRig with other payloads such as Vidar. It has also been deployed after exploitation of enterprise software vulnerabilities, including GitLab and TeamCity-related attack chains, and in cloud compromises affecting exposed EC2 instances.
In malicious operations, XMRig is typically used for resource hijacking and monetization through unauthorized mining. Threat actors often deliver it through loaders, downloaders, trojans, botnets, or propagation malware rather than relying on XMRig alone as the initial intrusion tool. Observed campaigns have included Windows and Linux infections, with Linux-focused activity frequently using SSH scanning, brute-force, and worm-like propagation to spread miners across poorly managed servers. On Windows, XMRig has appeared in campaigns using fake cracked-software lures, DLL sideloading, hidden PowerShell staging, scheduled tasks, service-based persistence, and file-hiding techniques. On Linux, customized variants have used disguised process names, watchdog behavior, cron jobs, and systemd services to maintain execution and restore deleted miner components.
XMRig is frequently paired with defense-evasion and persistence mechanisms added by operators or wrapper malware. These include process masquerading, hidden or renamed binaries, lock files, watchdog components, startup persistence, scheduled execution, and service installation. Some actor-modified builds embed mining configuration internally or are launched through helper tools that alter visible process names. XMRig has also been incorporated into broader malware ecosystems associated with botnets and financially motivated intrusion sets, including Sysrv-related activity, Phorpiex-linked campaigns, Vidar affiliate operations, and Linux server compromises involving ShellBot, MIG LogCleaner, and XHide.
Targets are opportunistic and broad, including consumers, SMBs, software developers, Linux server operators, CI/CD infrastructure, web servers, and cloud workloads. In many incidents, XMRig is not the sole objective but part of a dual-monetization model alongside credential theft, spyware, or remote access tooling. Its prevalence in post-compromise activity makes it a common indicator of unauthorized resource consumption and broader host compromise.
C2 tracking
Derp observations, rolling seven-day window
Samples
0d1777618ee58fc227ccb032d86c3b17383f21a8f60c0ac6a215bcf62b4a2801 32d2a6f7ae17283a18afd0f5130d4f34b1df6387dce9c0924e855b0cc677ce04 332b7962dbbb97b3a48e02417df8eada4f00d7a86114ab9b828cf234f6954049 633d0e7e1cf47e8d4b5bd79ea08b3afc3c60b2bb7cdcb3582cdbcffd7a5a0999 7553fb267f291580db633b1e3891164896ee3a5d0e86dcb854a72a3bb0f528a3 27dc2e511f4da03bc10b975156996133c8654defc24d40b829ff7d955be4e2ce 2e74827318235a497133219963a2205cd8d7779a195ec67d740d825599210932 5594d4a2153e25d5de0de21bc958e1d11a341679ea2fec2123567fa3547c7847 7ef34bf0c59089432586e8847b5a8d7439a28ed3aca3254fab49ef13723be65e c4617e465670873ca7de2d8898e8c349d8189b86561fc5b8996c4d8bab251801 Reported operators
The observed tactics, targeting, and tradecraft closely align with the Rare Werewolf (Librarian Ghouls) threat actor, although no XMRig cryptomining activity was observed in this sample.
The observed tactics, targeting, and tradecraft closely align with the Rare Werewolf (Librarian Ghouls) threat actor, although no XMRig cryptomining activity was observed in this sample.
Blue Mockingbird has made their XMRIG payloads persistent as a Windows Service.
By querying the hash on threat intelligence portals and by statically analyzing the sample, it became clear that this binary is a malicious modified version of XMRig (6.19.0), a cryptocurrency miner.
One of the campaigns deployed an XMRig cryptocurrency miner on a small number of infected machines, which is not standard behavior for a disciplined intelligence operation.
Impact T1496 Resource Hijacking TeamPCP kills competing XMRig cryptominers before deploying own payloads
If the CVE-2022-26134 vulnerability attack succeeds, the following PowerShell command downloads and executes additional PowerShell scripts and ultimately installs XMRig CoinMiner.
xmr.exe (7MB) -- XMRig Miner Binary (PE32+ x64)
Cryptominer Deployment The platform deploys a custom cryptomining agent to compromised hosts... Architecture Component Detail Agent Binary multimmm-user (custom Go binary) Miner XMRig (Monero)
In one case, investigators detected the use of XMRig, a legitimate cryptocurrency mining tool, suggesting attackers may have used victims’ computing resources to generate digital currency.
...as well as a custom .NET-based XMRig loader...
XMRig is an open-source Monero mining application frequently abused by cybercriminals. TeamPCP deploys XMRig on compromised hosts to mine Monero using the victim’s CPU resources without authorization.
XMRig is an open-source Monero mining application frequently abused by cybercriminals. TeamPCP deploys XMRig on compromised hosts to mine Monero using the victim’s CPU resources without authorization.
XMRig is an open-source Monero mining application frequently abused by cybercriminals. TeamPCP deploys XMRig on compromised hosts to mine Monero using the victim’s CPU resources without authorization.
XMRig is an open-source Monero mining application frequently abused by cybercriminals. TeamPCP deploys XMRig on compromised hosts to mine Monero using the victim’s CPU resources without authorization.
CRYSTALRAY has two associated cryptominers... (IoCs include xmrig_arm64 and xmrig_freebsd binaries).
DreamBus botnet was observed leveraging an CVE-2023-33246 exploit to drop XMRig Monero miners on vulnerable servers.
C:\Users\Public\ProgramData\xmrig.exe та (tcp)://xmr.2miners[.]com:2222
It uses XMRig to mine for Monero and makes sure that it uses only 60% of the processing power to evade immediate detection.
“CoinMiner XMRig, a CoinMiner that mines the Monero cryptocurrency, was the one the most used in the attacks.”
"TsunamiHardener... sets up... Microsoft Defender exclusions for TsunamiClient and the XMRig miner"
The code references XMRig, an open-source tool commonly used to mine Monero (XMR), and several Rusich-linked addresses have received funds from mining pools.
The code references XMRig, an open-source tool commonly used to mine Monero (XMR), and several Rusich-linked addresses have received funds from mining pools.
Exploited software
MITRE ATT&CK
Reporting
Commodity-Payload Command-and-Control, Distribution and Dead-Drop Resolvers (Delivered Malware) XMRig (Monero): pool.supportxmr.com:3333
Криптоджекинг (T1496, Resource Hijacking). Развёртывание XMRig - самый частый сценарий.
Rezet (Rare Werewolf) ... развёртывание XMRig-майнера
It deploys open-source miners such as XMRig, T-Rex, and TeamRedMiner.
ASEC identified cases where malware with propagation capabilities was used to install the XMRig CoinMiner.
Analysis of sysfrodolv.exe reveals that it downloads a malicious XMRig miner... Finally, the malware launches XMRig with specific mining parameters.
This is done when the malware downloads a separate component that installs mining software based on XMRig, T-Rex, or TeamRedMiner.
The threat actor also downloaded the XMRig cryptocurrency miner (xmr-1.zip) to the endpoint.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.