CoinMiner is a broad cryptocurrency-mining malware family name used for malicious miners that monetize compromised systems by hijacking compute resources. It is most commonly associated with Windows intrusions, where it has been observed spreading laterally through Windows Management Instrumentation and, in some reporting, EternalBlue-enabled propagation. CoinMiner variants commonly establish persistence through WMI Standard Event Consumer scripting and are frequently deployed after initial compromise rather than serving as the first-stage payload.
Operationally, CoinMiner appears across multiple intrusion types and criminal ecosystems. It has been delivered by other malware families and loaders, including services such as TrickGate and botnets such as Amadey, and has also appeared in opportunistic compromises of exposed services such as internet-facing MS-SQL servers. In those cases, attackers have used CoinMiner as an immediate monetization payload while retaining the option to escalate to broader post-compromise activity, including privilege escalation, remote access tooling, credential theft by companion malware, or ransomware deployment. CoinMiner has also been associated with campaigns following fake-update style malware chains and with malspam-driven distribution.
The family is heterogeneous, and capabilities vary by variant and operator. High-confidence behaviors include cryptocurrency mining, network propagation within Windows environments, and persistence via WMI-based mechanisms. Reporting also places CoinMiner in Linux threat telemetry and in campaigns that simultaneously targeted Windows and Android delivery infrastructure, but the strongest and most consistent association is with Windows-based cryptomining activity. CoinMiner has been prevalent in enterprise and public-sector malware reporting over multiple years, reflecting its continued utility as a low-friction monetization payload for both opportunistic and more structured threat operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CoinMiner is a cryptocurrency miner family that typically uses Windows Management Instrumentation (WMI) and EternalBlue to spread across a network.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
50 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A coin-mining malware category/name referenced as one of the main threats in the observed Linux SSH attacks.
CoinMiner is used for cryptocurrency mining and immediate monetization, and in this campaign it is signed with a stolen AnyDesk certificate to blend in.
CoinMiner is a generic term for malware that mines cryptocurrency on infected systems, often Monero or other privacy coins.
Cryptocurrency mining malware that spreads via malspam or is dropped by other malware, often using WMI for lateral movement and persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.