CoinMiner is a generic cryptocurrency-mining malware family name used for multiple variants that monetize compromised systems by hijacking compute resources. It is most commonly associated with Windows infections, though some reporting also uses the label more broadly for Linux-focused mining activity. CoinMiner infections have been observed as standalone payloads, as secondary payloads dropped by other malware, and as part of opportunistic post-compromise monetization on exposed services such as MS-SQL and Exchange servers.
On Windows, CoinMiner variants are repeatedly described as spreading laterally through Windows Management Instrumentation and, in some cases, EternalBlue-enabled propagation. Persistence has been associated with WMI Standard Event Consumer scripting. Delivery has been linked to malspam, phishing-adjacent lure chains, fake or compromised software distribution, and installation by other malware families or loaders. CoinMiner payloads have also appeared in campaigns using packers and loaders such as TrickGate, and in multi-stage botnet ecosystems such as Amadey, where mining provides immediate revenue alongside credential theft and access resale.
Operationally, CoinMiner is frequently used by financially motivated actors as a low-friction monetization step after initial access. Intrusions have shown CoinMiner deployed against internet-exposed MS-SQL servers, sometimes followed by privilege escalation and additional remote-control tooling. Other campaigns have paired CoinMiner with broader malware distribution, including Android-targeting infrastructure, or embedded mining components into destructive malware variants. Reporting also places CoinMiner among common threats observed against Linux SSH-exposed environments, although the specific family boundaries under this label vary by vendor.
Because "CoinMiner" is often used as a broad detection or family label rather than a single well-bounded codebase, capabilities can differ across variants. High-confidence common traits are cryptocurrency mining, network propagation in some Windows variants, and persistence through WMI-based mechanisms.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Microsoft Threat Intelligence identified and tracked exploitation of CVE-2026-73570, an unauthenticated OS command injection vulnerability in the Zimbra Collaboration Suite SNMP notification path. Exploitation can be triggered by a specially crafted email against internet-facing Zimbra servers when the optional zimbra-snmp package is installed and SNMP notifications are enabled.
CoinMiner is a cryptocurrency miner family that typically uses Windows Management Instrumentation (WMI) and EternalBlue to spread across a network.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
54 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A coin-mining malware category/name referenced as one of the main threats in the observed Linux SSH attacks.
Detected family name for malicious files in the sample set; no specific operational role in the airline intrusion is established in the content.
CoinMiner is used for cryptocurrency mining and immediate monetization, and in this campaign it is signed with a stolen AnyDesk certificate to blend in.
CoinMiner is a generic term for malware that mines cryptocurrency on infected systems, often Monero or other privacy coins.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.