Skip to content
Malware family CloudLinuxWindows

XMRig

XMRig is an open-source cryptocurrency mining program primarily used to mine Monero and other RandomX or CryptoNight-family coins.

Profile source: Mallory opens in a new tab

XMRig

Family profile

XMRig is an open-source cryptocurrency mining program primarily used to mine Monero and other RandomX or CryptoNight-family coins. Although legitimate in benign mining contexts, it is widely abused by threat actors as a cryptomining payload after host compromise. Intrusions involving XMRig commonly follow exploitation of internet-facing services, brute-force or credential-based access to Linux SSH servers, SQL injection against web applications, supply-chain compromise, downloader-based malware chains, and malvertising campaigns that bundle XMRig with other payloads such as Vidar. It has also been deployed after exploitation of enterprise software vulnerabilities, including GitLab and TeamCity-related attack chains, and in cloud compromises affecting exposed EC2 instances.

In malicious operations, XMRig is typically used for resource hijacking and monetization through unauthorized mining. Threat actors often deliver it through loaders, downloaders, trojans, botnets, or propagation malware rather than relying on XMRig alone as the initial intrusion tool. Observed campaigns have included Windows and Linux infections, with Linux-focused activity frequently using SSH scanning, brute-force, and worm-like propagation to spread miners across poorly managed servers. On Windows, XMRig has appeared in campaigns using fake cracked-software lures, DLL sideloading, hidden PowerShell staging, scheduled tasks, service-based persistence, and file-hiding techniques. On Linux, customized variants have used disguised process names, watchdog behavior, cron jobs, and systemd services to maintain execution and restore deleted miner components.

XMRig is frequently paired with defense-evasion and persistence mechanisms added by operators or wrapper malware. These include process masquerading, hidden or renamed binaries, lock files, watchdog components, startup persistence, scheduled execution, and service installation. Some actor-modified builds embed mining configuration internally or are launched through helper tools that alter visible process names. XMRig has also been incorporated into broader malware ecosystems associated with botnets and financially motivated intrusion sets, including Sysrv-related activity, Phorpiex-linked campaigns, Vidar affiliate operations, and Linux server compromises involving ShellBot, MIG LogCleaner, and XHide.

Targets are opportunistic and broad, including consumers, SMBs, software developers, Linux server operators, CI/CD infrastructure, web servers, and cloud workloads. In many incidents, XMRig is not the sole objective but part of a dual-monetization model alongside credential theft, spyware, or remote access tooling. Its prevalence in post-compromise activity makes it a common indicator of unauthorized resource consumption and broader host compromise.

Capabilities

  • Defense Evasion
  • Persistence
  • Post Exploitation

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 14, 2026
Last activity
Jul 21, 2026
Feed role
C2 / Distribution
Host form
37 IP / 31 hostnames

Leading locations

  • CN15
  • US9
  • DE7
  • NL5
  • KR4
  • JP3
  • RU3
  • FR2
  • IT2
  • KG2
  • LU2
  • TN2

Leading providers

  • Hangzhou Alibaba Advertising Co.,Ltd.5
  • Shenzhen Tencent Computer Systems Company Limited5
  • CHINA UNICOM China169 Backbone4
  • Omegatech LTD3
  • SK Broadband Co Ltd3
  • 3S INF2

Infrastructure traits

  • Hosting 43
  • Vpn 7
  • Anycast 5
  • Mobile 2
  • Proxy 1

Samples

Recent associated samples

Reported operators

Threat actors

23 named in public reporting
Rare Werewolf

The observed tactics, targeting, and tradecraft closely align with the Rare Werewolf (Librarian Ghouls) threat actor, although no XMRig cryptomining activity was observed in this sample.

Librarian Ghouls

The observed tactics, targeting, and tradecraft closely align with the Rare Werewolf (Librarian Ghouls) threat actor, although no XMRig cryptomining activity was observed in this sample.

Blue Mockingbird

Blue Mockingbird has made their XMRIG payloads persistent as a Windows Service.

Outlaw

By querying the hash on threat intelligence portals and by statically analyzing the sample, it became clear that this binary is a malicious modified version of XMRig (6.19.0), a cryptocurrency miner.

GREYVIBE

One of the campaigns deployed an XMRig cryptocurrency miner on a small number of infected machines, which is not standard behavior for a disciplined intelligence operation.

TeamPCP

Impact T1496 Resource Hijacking TeamPCP kills competing XMRig cryptominers before deploying own payloads

8220 Gang

If the CVE-2022-26134 vulnerability attack succeeds, the following PowerShell command downloads and executes additional PowerShell scripts and ultimately installs XMRig CoinMiner.

TWIZT

xmr.exe (7MB) -- XMRig Miner Binary (PE32+ x64)

xssNew

Cryptominer Deployment The platform deploys a custom cryptomining agent to compromised hosts... Architecture Component Detail Agent Binary multimmm-user (custom Go binary) Miner XMRig (Monero)

UAC-0247

In one case, investigators detected the use of XMRig, a legitimate cryptocurrency mining tool, suggesting attackers may have used victims’ computing resources to generate digital currency.

REF1695

...as well as a custom .NET-based XMRig loader...

Kinsing

XMRig is an open-source Monero mining application frequently abused by cybercriminals. TeamPCP deploys XMRig on compromised hosts to mine Monero using the victim’s CPU resources without authorization.

APT4

XMRig is an open-source Monero mining application frequently abused by cybercriminals. TeamPCP deploys XMRig on compromised hosts to mine Monero using the victim’s CPU resources without authorization.

APT41

XMRig is an open-source Monero mining application frequently abused by cybercriminals. TeamPCP deploys XMRig on compromised hosts to mine Monero using the victim’s CPU resources without authorization.

Pacha Group

XMRig is an open-source Monero mining application frequently abused by cybercriminals. TeamPCP deploys XMRig on compromised hosts to mine Monero using the victim’s CPU resources without authorization.

CRYSTALRAY

CRYSTALRAY has two associated cryptominers... (IoCs include xmrig_arm64 and xmrig_freebsd binaries).

DreamBus

DreamBus botnet was observed leveraging an CVE-2023-33246 exploit to drop XMRig Monero miners on vulnerable servers.

UAC-0006

C:\Users\Public\ProgramData\xmrig.exe та (tcp)://xmr.2miners[.]com:2222

IronErn440

It uses XMRig to mine for Monero and makes sure that it uses only 60% of the processing power to evade immediate detection.

LemonDuck

“CoinMiner XMRig, a CoinMiner that mines the Monero cryptocurrency, was the one the most used in the attacks.”

Contagious Interview

"TsunamiHardener... sets up... Microsoft Defender exclusions for TsunamiClient and the XMRig miner"

Wagner

The code references XMRig, an open-source tool commonly used to mine Monero (XMR), and several Rusich-linked addresses have received funds from mining pools.

Task Force Rusich

The code references XMRig, an open-source tool commonly used to mine Monero (XMR), and several Rusich-linked addresses have received funds from mining pools.

Exploited software

Vulnerabilities linked to XMRig

28 CVEs
CVE-2021-22205 GitLab CE/EE ExifTool Image Parsing Remote Code Execution CVE-2024-27198 Authentication Bypass in JetBrains TeamCity On-Premises CVE-2024-4577 PHP-CGI Argument Injection RCE on Windows CVE-2026-33017 Unauthenticated RCE in Langflow public flow build endpoint CVE-2025-55182 React2Shell CVE-2025-31324 Unauthenticated Arbitrary File Upload in SAP NetWeaver Visual Composer Metadata Uploader CVE-2021-41285 Privilege Escalation in Ballistix MOD Utility MODAPI.sys Driver CVE-2020-14979 Local Privilege Escalation in EVGA Precision X1 WinRing0 Driver CVE-2021-44228 Log4Shell CVE-2022-26134 Atlassian Confluence Server and Data Center OGNL Injection RCE CVE-2026-20122 Arbitrary File Overwrite in Cisco Catalyst SD-WAN Manager API CVE-2026-20133 Information Disclosure in Cisco Catalyst SD-WAN Manager CVE-2026-20128 Information Disclosure in Cisco Catalyst SD-WAN Manager Data Collection Agent CVE-2024-0012 Authentication Bypass in Palo Alto Networks PAN-OS Management Web Interface CVE-2024-9474 Privilege Escalation in Palo Alto Networks PAN-OS Management Web Interface CVE-2022-22954 VMware Workspace ONE Access and Identity Manager Server-Side Template Injection RCE CVE-2023-33246 Unauthenticated RCE in Apache RocketMQ update configuration CVE-2023-38646 Unauthenticated Command Injection in Metabase Setup Validation CVE-2023-48022 Unauthenticated RCE in Anyscale Ray Job Submission API CVE-2026-20182 Authentication Bypass in Cisco Catalyst SD-WAN Peering Handshaking CVE-2024-3400 Unauthenticated RCE in Palo Alto PAN-OS GlobalProtect CVE-2025-29927 Authorization Bypass in Next.js Middleware CVE-2018-7600 Drupalgeddon2 CVE-2020-35489 Unrestricted File Upload in Contact Form 7 for WordPress CVE-2024-23692 Unauthenticated RCE in Rejetto HTTP File Server via Template Injection CVE-2025-24893 Unauthenticated RCE in XWiki SolrSearch CVE-2021-24284 Unauthenticated Arbitrary File Upload in Kaswara Modern VC Addons WordPress Plugin CVE-2025-32432 Pre-authentication RCE in Craft CMS generate-transform

MITRE ATT&CK

XMRig in ATT&CK

92 distinct techniques

Techniques

92 techniques
T1496 Resource Hijacking T1027 Obfuscated Files or Information T1053.005 Scheduled Task T1033 System Owner/User Discovery T1553.002 Code Signing T1497.001 System Checks T1497 Virtualization/Sandbox Evasion T1190 Exploit Public-Facing Application T1105 Ingress Tool Transfer T1071 Application Layer Protocol T1070.004 File Deletion T1110 Brute Force T1021 Remote Services T1059.003 Windows Command Shell T1564 Hide Artifacts T1222 File and Directory Permissions Modification T1036 Masquerading T1543 Create or Modify System Process T1195 Supply Chain Compromise T1204 User Execution T1560 Archive Collected Data T1133 External Remote Services T1078 Valid Accounts T1059 Command and Scripting Interpreter T1210 Exploitation of Remote Services T1110.001 Password Guessing T1046 Network Service Discovery T1059.004 Unix Shell T1021.004 SSH T1583 Acquire Infrastructure T1547.001 Registry Run Keys / Startup Folder T1562.001 Disable or Modify Tools T1053 Scheduled Task/Job T1562 Impair Defenses T1082 System Information Discovery T1620 Reflective Code Loading T1070 Indicator Removal T1203 Exploitation for Client Execution T1568.002 Domain Generation Algorithms T1059.005 Visual Basic T1053.002 At T1546.003 Windows Management Instrumentation Event Subscription T1115 Clipboard Data T1059.001 PowerShell T1021.001 Remote Desktop Protocol T1057 Process Discovery T1055 Process Injection T1574.012 COR_PROFILER T1204.002 Malicious File T1014 Rootkit T1189 Drive-by Compromise T1489 Service Stop T1027.002 Software Packing T1547 Boot or Logon Autostart Execution T1564.001 Hidden Files and Directories T1543.003 Windows Service T1568 Dynamic Resolution T1055.012 Process Hollowing T1566.002 Spearphishing Link T1021.002 SMB/Windows Admin Shares T1047 Windows Management Instrumentation T1550.002 Pass the Hash T1588.002 Tool T1027.011 Fileless Storage T1611 Escape to Host T1053.003 Cron T1543.002 Systemd Service T1112 Modify Registry T1091 Replication Through Removable Media T1570 Lateral Tool Transfer T1037 Boot or Logon Initialization Scripts T1068 Exploitation for Privilege Escalation T1195.001 Compromise Software Dependencies and Development Tools T1566 Phishing T1553.005 Mark-of-the-Web Bypass T1071.001 Web Protocols T1083 File and Directory Discovery T1218 System Binary Proxy Execution T1560.001 Archive via Utility T1543.001 Launch Agent T1102 Web Service T1572 Protocol Tunneling T1584.004 Server T1140 Deobfuscate/Decode Files or Information T1518 Software Discovery T1565.002 Transmitted Data Manipulation T1222.001 Windows File and Directory Permissions Modification T1531 Account Access Removal T1059.006 Python T1222.002 Linux and Mac File and Directory Permissions Modification T1609 Container Administration Command T1090.003 Multi-hop Proxy

Reporting

Research mentioning XMRig

Jul 20
Vmray

A single RedLine C2 from UniqueSignal pivots into a maritime spear-phishing cluster and attacker-owned infrastructure.

Commodity-Payload Command-and-Control, Distribution and Dead-Drop Resolvers (Delivered Malware) XMRig (Monero): pool.supportxmr.com:3333

Jul 19
Codeby

cPanel уязвимость: CRLF-инъекция → root → криптомайнинг

Криптоджекинг (T1496, Resource Hijacking). Развёртывание XMRig - самый частый сценарий.

Jul 19
Codeby

APT-группировки 2025: кампании, TTP и threat intelligence

Rezet (Rare Werewolf) ... развёртывание XMRig-майнера

Jul 17
Security Online Info

Supply Chain Trojan Targets Software Developers

It deploys open-source miners such as XMRig, T-Rex, and TeamRedMiner.

Jul 15
Malware News

Case Study: Distribution of a CoinMiner Targeting Linux SSH Servers via Malware Distribution via Network Transmission - Malware Analysis - Malware Analysis, News and Indicators

ASEC identified cases where malware with propagation capabilities was used to install the XMRig CoinMiner.

Jul 14
Pointwild

Phorpiex: Inside the Botnet Powering Global Sextortion Spam Operations | Point Wild

Analysis of sysfrodolv.exe reveals that it downloads a malicious XMRig miner... Finally, the malware launches XMRig with specific mining parameters.

Jul 13
Hackread

Siggen Backdoor Hits Windows Developers Via Infected Visual Studio Projects

This is done when the malware downloads a separate component that installs mining software based on XMRig, T-Rex, or TeamRedMiner.

Jul 13
Huntress

Threat Actors Achieve Persistence After SQL Injection | Huntress

The threat actor also downloaded the XMRig cryptocurrency miner (xmr-1.zip) to the endpoint.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.