Last seven days
- First activity
- Aug 22, 2026
- Last activity
- Aug 29, 2026
- Feed role
- C2 / Distribution
- Host form
- 137 IP / 115 hostnames
XMRig is an open-source, cross-platform cryptocurrency-mining application primarily used to mine Monero and other RandomX-based currencies.
Profile source: Mallory opens in a new tabXMRig
XMRig is an open-source, cross-platform cryptocurrency-mining application primarily used to mine Monero and other RandomX-based currencies. Although legitimate mining software, it is frequently deployed without authorization by opportunistic cybercriminals following exploitation of exposed services, vulnerable applications, cloud and container workloads, and compromised endpoints. Observed abuse includes use on Linux, Windows, and macOS systems, often with CPU-tuning options intended to improve RandomX mining performance. Operators commonly rename or stage XMRig to resemble legitimate software, run it detached or through persistence mechanisms, remove competing miners, and configure it to connect to attacker-controlled mining pools. XMRig has appeared as a payload in campaigns targeting AI infrastructure, internet-exposed macOS Screen Sharing services, vulnerable Java applications, social-media-propagated malware infections, and trojanized software-update ecosystems.
C2 tracking
Derp observations, rolling seven-day window
Samples
01084fc2d07324a138fbed21d26e964776c855c5714ae4d4001d92217510f812 070bae49e119eb2a6444c54f9257b6e7647802a94966f8782527719edd664e2f 9d97136b1bfa10503de41bc6feb6c129cae45cbb552045bab3283db36b372d4f c6783ae783ef86c90fc166a16bdc9b243fa3d337efeb7cbfce230ae1a8506426 db47d24c3fb20d06176f3fd8714ff12378050b070ad1da1aec8dc483990e7673 3ac88750fa45ff75a48bdc047c9e634428ba56f283c0dedc7120a3189150fc2a d087addae8df77b58cf199f0ab409072002712cc19a58fbcc1a3c080d54d4076 ea62e2023e870ecb8527e5cc1b2a371df755edce1d4412a444d7d71ae60d1c36 ed18581698b8a24b5e88b883f0481a22ccc6e4d8bafcf01096cbafed7792ac83 ed9c2fad37ee2a20561c9e5584e5d48d47a73ab5f14f9b51e2676cdf07389d47 Reported operators
“Revenue came from three sources. XMRig mining paid little. A rented proxy network brought in more.”
the affected victim server subsequently made a DNS query to us‐nation‐ny[.]cf... and then subsequently executed PowerShell commands enabling the threat actors to download and execute additional malicious files, including the XMRig crypto mining software.
the affected victim server subsequently made a DNS query to us‐nation‐ny[.]cf... and then subsequently executed PowerShell commands enabling the threat actors to download and execute additional malicious files, including the XMRig crypto mining software.
RAGE est un framework Python personnalisé, généré avec l’aide de l’IA, ciblant des services exposés (...) pour déployer XMRig.
Blue Mockingbird has executed custom-compiled XMRIG miner DLLs using rundll32.exe.
The code shown below highlights how TeamTNT installed a cryptominer on the compromised pod running in the active node of the Kubernetes cluster. The module reflects how the xmrig.tgz file is downloaded and the cryptominer is installed on the compromised pod.
The cryptocurrency miner XMRig has been staged in the past on a command and control (C&C) server by TA427, but it was never confirmed if actors deployed it in the wild.
Although Pro-Ocean attempts to disguise itself as benign, it packs an XMRig miner, which is notorious for its use in cryptojacking operations.
In the latest code downloaded (January 12, 2021), it seems that the malware tries to exploit the vulnerabilities to install the Xmrig from the server hxxp://gxbrowser[.]net.
IronNet observed what appeared to be a number of different botnets, in some cases pushing the same shell script but always ultimately leading to a XMRig coinminer.
On September 16, XMRig, the most common Monero (XMR) miner, was installed by Emotet using command 2 which is just for loading modules.
Case 1 - XMRig ... Xmrig.exe is part of XMRig open-source CPU/GPU cryptocurrency mining software ... The downloaded payload is XMRig miner.
Exploitation of the vulnerability in VMware Horizon allowed the attackers to install the XMRIG cryptocurrency miner to a system.
In many cases, this includes the RedLine Stealer and an XMRig-based cryptocurrency mining malware that is internally referred to as "ZingoMiner."
Case 1 - XMRig ... Xmrig.exe is part of XMRig open-source CPU/GPU cryptocurrency mining software ... The downloaded payload is XMRig miner.
During the course of our research, we also discovered evidence suggesting that the Tor2Mine actors are deploying additional malware in tandem with XMRig during their operations to harvest credentials and steal more money.
We observed that the payload itself illicitly mined Monero using XMRig, an open-source and multiplatform Monero miner.
We were able to obtain and decrypt the .mui files loaded by Win64/Winnti.BN. They were actually XMRig executables, again packed using the same custom packer as the one used to pack the 1st stage of compromised games as well as the PortReuse backdoor.
Database server misused to mine Monero via the coinminer file xmrig-2.5.3-xenial-amd64.tar ... The corresponding wallet address was found with 1.161 XMR at the time of writing.
Imperva security researchers were able to identify attackers’ attempts to exploit this vulnerability in order to install and run the XMRig cryptocurrency miner on affected Confluence servers running on Windows and Linux systems.
经过分析,该样本确认为 XMRig 挖矿木马,木马自带配置文件并且支持通过硬编码URL远程更新配置信息。
经过分析,该样本确认为 XMRig 挖矿木马,木马自带配置文件并且支持通过硬编码URL远程更新配置信息。
The deployment of an XMRig miner payload on a small number of LegionRelay-infected machines.
the AhnLab SEcurity intelligence Center (ASEC) identified an instance in which the Larva-26009 threat actor installed the XMRig CoinMiner.
Il dépose entre 40 et 50 exécutables ... et installe simultanément plusieurs familles de malwares : XMRig v6.2.2 (minage Monero, pool pool.supportxmr.com:3333 )
The packages copied legitimate Ruby libraries and altered their entry-point files to launch mining code... Download URL raw.githubusercontent.com/xmrig/xmrig/v6.22.2/xmrig-6.22.2-linux-static-x64.tar.gz Miner archive download location
The packages copied legitimate Ruby libraries and altered their entry-point files to launch mining code... Download URL raw.githubusercontent.com/xmrig/xmrig/v6.22.2/xmrig-6.22.2-linux-static-x64.tar.gz Miner archive download location
Криптоджекинг (T1496, Resource Hijacking). Развёртывание XMRig - самый частый сценарий.
Rezet (Rare Werewolf) ... развёртывание XMRig-майнера
Rezet (Rare Werewolf) ... развёртывание XMRig-майнера
The observed tactics, targeting, and tradecraft closely align with the Rare Werewolf (Librarian Ghouls) threat actor, although no XMRig cryptomining activity was observed in this sample.
If the CVE-2022-26134 vulnerability attack succeeds, the following PowerShell command downloads and executes additional PowerShell scripts and ultimately installs XMRig CoinMiner.
xmr.exe (7MB) -- XMRig Miner Binary (PE32+ x64)
Cryptominer Deployment The platform deploys a custom cryptomining agent to compromised hosts... Architecture Component Detail Agent Binary multimmm-user (custom Go binary) Miner XMRig (Monero)
In one case, investigators detected the use of XMRig, a legitimate cryptocurrency mining tool, suggesting attackers may have used victims’ computing resources to generate digital currency.
...as well as a custom .NET-based XMRig loader...
XMRig is an open-source Monero mining application frequently abused by cybercriminals. TeamPCP deploys XMRig on compromised hosts to mine Monero using the victim’s CPU resources without authorization.
XMRig is an open-source Monero mining application frequently abused by cybercriminals. TeamPCP deploys XMRig on compromised hosts to mine Monero using the victim’s CPU resources without authorization.
CRYSTALRAY has two associated cryptominers... (IoCs include xmrig_arm64 and xmrig_freebsd binaries).
DreamBus botnet was observed leveraging an CVE-2023-33246 exploit to drop XMRig Monero miners on vulnerable servers.
C:\Users\Public\ProgramData\xmrig.exe та (tcp)://xmr.2miners[.]com:2222
It uses XMRig to mine for Monero and makes sure that it uses only 60% of the processing power to evade immediate detection.
“CoinMiner XMRig, a CoinMiner that mines the Monero cryptocurrency, was the one the most used in the attacks.”
"TsunamiHardener... sets up... Microsoft Defender exclusions for TsunamiClient and the XMRig miner"
The code references XMRig, an open-source tool commonly used to mine Monero (XMR), and several Rusich-linked addresses have received funds from mining pools.
The code references XMRig, an open-source tool commonly used to mine Monero (XMR), and several Rusich-linked addresses have received funds from mining pools.
Exploited software
MITRE ATT&CK
Reporting
Microsoft observed intrusions targeting exposed LiteLLM, RAGFlow, and Kestra AI control-plane workloads to obtain credentials, establish persistence, access downstream data, and deploy cryptocurrency-mining tools. In the LiteLLM case, attackers likely exploited an exposed gateway, harvested runtime and PostgreSQL secrets, deployed XMRig-like tooling, and persisted through SSH keys, cron modifications, hidden files, and immutable file attributes. In a RAGFlow environment, attackers conducted SSRF-style reconnaissance and modified the application to persistently intercept newly configured LLM-provider credentials; Microsoft did not confirm the code-execution vulnerability used. A Kestra intrusion was assessed as likely exploiting CVE-2026-49869 to bypass authentication, run malicious workflows, access Docker container environments, deploy XMRig, and collect data through Kestra's key-value interface. Microsoft advised treating AI gateways, retrieval platforms, and workflow orchestrators as critical control-plane infrastructure because they centralize privileged execution and high-value secrets.
Researchers reported multiple social-engineering campaigns targeting macOS users with fake CAPTCHA and ClickFix lures that trick victims into copying and pasting malicious commands into Terminal, shifting execution to the user and bypassing traditional app-download protections. One campaign delivered Atomic macOS Stealer (AMOS) through trojanized cracked applications and malicious Terminal instructions, stealing credentials, browser data, cryptocurrency wallets, Telegram data, VPN profiles, keychain contents, Apple Notes, and files from common user folders before compressing and exfiltrating them over HTTP/HTTPS. Trend Micro separately documented multistage fake CAPTCHA attacks that also led to infostealers and remote-access trojans, underscoring the broader use of human-verification themes to launch malware chains. A separate July 2026 macOS campaign used a fake TrustKey verification page on Cloudflare Pages, a Cloudflare Worker, and an AppleScript-based loader to install a persistent backdoor named bmodule via LaunchAgent persistence. The malware dynamically resolved live command-and-control infrastructure from a Polygon smart contract using an EtherHiding technique, then fingerprinted hosts, phished macOS login passwords, and fetched tasks to deploy AMOS variants, an interactive shell, or an XMRig cryptominer. Apple said macOS Sequoia has updated runtime protections, while incident reporting shows Terminal-based social-engineering chains remain effective because they rely on users to execute the malicious commands directly.
A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.
Brazilian educational institutions faced a sustained wave of cyber incidents in incident-response cases reviewed from January 2025 through June 2026, with attackers most often gaining access through valid accounts, exploitation of public-facing applications, insider activity, and weak patch management. High-severity cases were dominated by ransomware, particularly DragonForce and LockBit 3, and private institutions were more frequently affected than public ones. Investigators also found that outdated and unpatched systems, including Windows 10 deployments kept past end of support and unpatched Windows Server 2016 hosts, materially increased exposure. Representative intrusions showed attackers relying on common but effective techniques rather than novel tradecraft. One LockBit case involved a custom deployment built from the leaked builder and spread with PsExec, aligning with the well-documented abuse of Windows service execution for lateral movement and payload launch. Another DragonForce intrusion used AnyDesk and log wiping to maintain access and hinder response, while a separate insider case involved a Python keylogger installed on a shared machine to capture credentials. The findings underscore the need for MFA, least privilege, removal of shared accounts, tighter control of remote-access tools, stronger backups, centralized logging, longer EDR retention, and faster patching.
Researchers linked multiple Linux intrusions to a Romanian-speaking threat cluster that brute-forced weak SSH credentials, compromised servers and network devices at scale, and deployed a Perl-based Shellbot with IRC command-and-control. Trend Micro found infrastructure capable of generating target lists covering roughly 80 million IP addresses, logs indicating more than 65,000 potentially compromised hosts, and tooling including the Haiduc SSH brute-forcer, process-masquerading utility Faker, privilege-escalation exploits such as CVE-2017-16995 and Dirty Cow variants, and high-availability C2 built with CARP. Bitdefender separately tied a likely Romanian group to Linux-focused scanning, SHC-obfuscated loaders, Discord webhook reporting, a customized Perl IRC bot, and a Golang SSH bruteforcer offered in a SaaS-like model, with monetization centered on Monero mining via customized XMRig payloads. Additional reporting showed the campaign’s tradecraft remained active across traditional servers and cloud-native environments. JPCERT/CC documented attackers using stolen SSH access to move laterally, install XMRig, hide mining with XHide, tamper with logs, and continue scanning for new SSH targets, while Sysdig observed Shellbot compromise a Tomcat container through brute-forced default credentials, download multi-architecture payloads, establish persistence, erase traces, and receive commands for file transfer, port scanning, data exfiltration, and DDoS attacks. Together, the reports describe a long-running Linux-focused operation that blends brute-force access, worm-like propagation, cryptojacking, and botnet functionality across exposed infrastructure.
TeamTNT continued to evolve from a Linux-focused cryptojacking group into a broad cloud threat actor targeting exposed Redis, Docker, Kubernetes, Jupyter, Hadoop, PostgreSQL, Tomcat, Nginx, SSH, and other internet-facing services. Researchers tied the group to worm-like campaigns that rapidly scanned for vulnerable hosts, deployed XMRig miners, dropped Tsunami-based IRC bots including DDoS-capable variants, and used malicious container images on Docker Hub to spread payloads at scale. One TeamTNT-linked Docker Hub account reportedly served images pulled more than 150,000 times, while later campaigns showed the group abusing public registries, compromised accounts, and cloud-native tooling to infect newly exposed systems and report them back to command-and-control infrastructure. Across these operations, TeamTNT consistently paired monetization with aggressive credential theft and stealth. Investigations found the group harvesting AWS, Azure, GCP, Kubernetes, Git, NPM, Grafana, database, and storage secrets; stealing SSH keys and host data; and using tools such as Weave Scope, Peirates, BotB, MimiPenguin, Mimipy, tmate, and Gsocket to expand access and persistence. Analysts also documented detection evasion through log wiping, process hiding, LD_PRELOAD userland rootkits, the Diamorphine kernel rootkit, privileged containers with restart policies, and even disabling runc to lock out rival attackers, underscoring TeamTNT’s shift from opportunistic mining to sustained compromise of cloud and container environments.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.