Linuxsys cryptominer campaign is a long-running opportunistic coinmining operation active since at least 2021 that exploits multiple known vulnerabilities in internet-facing applications to deploy Monero-mining malware. The operation has used both Linux and Windows payloads and relies on a consistent intrusion workflow centered on n-day exploitation, staging payloads on previously compromised legitimate websites, and using scripts to maintain miner execution after reboot. The campaign is notable for operational stealth rather than scale, using legitimate web infrastructure and valid TLS certificates on compromised sites to blend malicious delivery into normal traffic and reduce detection. Observed tradecraft includes initial access through exploitation of public-facing applications, malware delivery from compromised third-party hosts, persistence via restart scripts and scheduled execution mechanisms, and post-compromise deployment of cryptomining binaries and configuration files. The actor has repeatedly refreshed staging infrastructure and payload variants while preserving the same overall methodology across several years. Reporting also indicates selective avoidance of low-interaction honeypots and a preference for higher-interaction targets, suggesting basic reconnaissance or target validation before full deployment. The campaign appears financially motivated and relatively small in scale compared with major botnet-driven mining operations, but it has remained active over multiple years with moderate success. Public reporting has also noted possible overlap or investigative interest involving the 8220 Mining Group, also known as Returned Libra, but a definitive attribution is not established at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.