XMRig is an open-source cryptocurrency mining application that is frequently repurposed by threat actors for unauthorized Monero mining on compromised systems. In malicious use, it is commonly deployed as a cryptominer payload after initial compromise rather than as a standalone intrusion platform. It has been observed across Windows and Linux environments, including on exposed cloud infrastructure, compromised servers, developer workstations, torrent clients, MS-SQL servers, and consumer endpoints reached through social-engineering campaigns.
Threat actors routinely adapt XMRig for stealth and operational control. Observed malicious variants have been modified to run from memory after deleting their on-disk binary, masquerade as legitimate processes, kill competing miners, obfuscate configuration data, and route mining traffic through actor-controlled proxy infrastructure. Linux-focused campaigns have used heavily modified XMRig builds with custom command-line options, CPU-aware tuning, Huge Pages allocation, and Model-Specific Register interaction to maximize mining performance while reducing visibility. Some operations have also paired XMRig with persistence mechanisms such as cron jobs, scheduled tasks, malicious plugins, or loader chains, and have disabled or weakened defensive controls to protect mining activity.
XMRig is delivered through a wide range of intrusion and malware-delivery ecosystems. Documented vectors include weak credentials on internet-exposed services, trojanized software packages, malicious RubyGems packages, ClickFix-style lures that trick users into executing PowerShell commands, DLL sideloading, and deployment by broader malware bundles or post-exploitation operators. It has also appeared in campaigns alongside infostealers, loaders, remote-access tools, web shells, and proxy tooling, reflecting its role as a monetization payload after access is established.
Multiple threat actors and campaigns have used XMRig, including opportunistic cloud intruders, actors targeting torrent clients and MS-SQL servers, supply-chain and post-exploitation operators, and large malware distribution operations such as Operation STANDOFF. In some cases, customized XMRig builds were integrated into botnet-style infrastructure or stealthy Linux cryptojacking campaigns that abused authentication mechanisms and low-privileged accounts to hinder detection and remediation. The primary impact is resource hijacking through unauthorized cryptocurrency mining, often accompanied by persistence, defense evasion, and additional malware activity on the same host.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
28 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Анатомия cPanel уязвимости CVE-2026-41940: как CRLF-инъекция даёт root на WHM CVE-2026-41940 - обход аутентификации (CWE-306, Missing Authentication for Critical Function), активно эксплуатируемая в дикой среде (CISA KEV), CVSS 9.3 по шкале 4.0. Затрагивает все версии cPanel/WHM начиная с 11.40, включая DNSOnly и WP Squared. | Криптоджекинг (T1496, Resource Hijacking). Развёртывание XMRig - самый частый сценарий.
Криптоджекинг (T1496, Resource Hijacking). Развёртывание XMRig - самый частый сценарий.
CVE-2021-22205 is a critical remote code execution vulnerability in the service’s web interface... GitLab amended the CVSSv3 score to 10.0... shifting the vulnerability from an authenticated to an unauthenticated condition... The entry point for this vulnerability is the POST request via /uploads/user endpoint.
APT29 (Cozy Bear) exploited CVE-2024-27198 in real-world campaigns.
In this case, the attacker was automatically trying to exploit CVE-2024-4577, which affects certain versions of PHP 8 when using Apache and PHP-CGI on Windows.
Threat actors are continuing to exploit a critical Langflow vulnerability as part of fresh attacks designed to deliver a Monero cryptocurrency miner. The activity has been found to weaponize CVE-2026-33017 (CVSS score: 9.3), an unauthenticated remote code execution (RCE) vulnerability in Langflow, indicating threat actors are scanning and targeting exposed artificial intelligence (AI) application endpoints for obtaining initial access to enterprise networks.
The React2Shell vulnerability (CVE-2025–55182) was reported to the React team on November 29. Public advisories and patches dropped on December 3. Threat actors started exploiting it within hours... React2Shell (CVE-2025–55182) is a critical, unauthenticated remote code execution bug in React Server Components’ “Flight” protocol. | Common post-exploitation moves: Install XMRig or another cryptominer
Along with patching, we recommend examining SAP web server access logs for additional evidence of CVE-2025-31324 exploitation, specifically looking for evidence of unusual requests to the API endpoint /developmentserver/metadatauploader . If possible, consider disallowing access to that API endpoint from external networks. To hunt for additional evidence of web shell uploads, organizations can search for unexpected JSP files within these folders on SAP servers... | hxxp[://]23.95.123[.]5:666/xmrigCCall/8bq.sh
This service is accompanied by a pipe named \\.\WinRing0_1_2_0 which allows the process to communicate with the driver. This is quite an old driver, vulnerable to CVE-2020-14979 and CVE-2021-41285, and allowing the actor to elevate privileges to NT\SYSTEM as soon as the direct unchecked communication with the driver is allowed and the attacker controls input forwarded to the driver.
This service is accompanied by a pipe named \\.\WinRing0_1_2_0 which allows the process to communicate with the driver. This is quite an old driver, vulnerable to CVE-2020-14979 and CVE-2021-41285, and allowing the actor to elevate privileges to NT\SYSTEM as soon as the direct unchecked communication with the driver is allowed and the attacker controls input forwarded to the driver.
Ahnlab Security Emergency response Center (ASEC) has recently confirmed that the 8220 Gang attack group is using the Log4Shell vulnerability to install CoinMiner in VMware Horizon servers. Log4Shell (CVE-2021-44228) is both a remote code execution vulnerability and the Java-based logging utility Log4j vulnerability... | If the CVE-2022-26134 vulnerability attack succeeds, the following PowerShell command downloads and executes additional PowerShell scripts and ultimately installs XMRig CoinMiner.
The group targets not only global systems but also Korean ones. ASEC has introduced a case where the attack group abused the Atlassian Confluence server vulnerability CVE-2022-26134 to attack Korean systems and install CoinMiner. | If the CVE-2022-26134 vulnerability attack succeeds, the following PowerShell command downloads and executes additional PowerShell scripts and ultimately installs XMRig CoinMiner.
In this cluster of activity, since at least March 25, 2026, an XMRig sample and its accompanying configuration file were downloaded and deployed via a shell script.
In this cluster of activity, since at least March 25, 2026, an XMRig sample and its accompanying configuration file were downloaded and deployed via a shell script.
In this cluster of activity, since at least March 25, 2026, an XMRig sample and its accompanying configuration file were downloaded and deployed via a shell script.
Several devices initiated TCP connections to endpoints affiliated with cryptomining pools such as us[.]zephyr[.]herominers[.]com and xmrig[.]com. Connectivity to these domains indicates likely successful installation of mining software during earlier stages of post-compromise activity.
Several devices initiated TCP connections to endpoints affiliated with cryptomining pools such as us[.]zephyr[.]herominers[.]com and xmrig[.]com. Connectivity to these domains indicates likely successful installation of mining software during earlier stages of post-compromise activity.
CVE-2022-22954, a remote code execution (RCE) vulnerability due to server-side template injection in VMware Workspace ONE Access and Identity Manager, is trivial to exploit with a single HTTP request to a vulnerable device.
Apache RocketMQ Exploit Module (CVE-2023-33246) ... In June 2023, a vulnerability cataloged as CVE-2023-33246 was discovered that enables an attacker to achieve remote command execution (RCE) on RocketMQ versions 5.1.0 and earlier. Shortly after, DreamBus added an exploit module to target this vulnerability.
Metabase Exploit Module (CVE-2023-38646) ... The open source versions of Metabase 0.46.6.1 and earlier, as well as Metabase Enterprise 1.46.6.1 and earlier, are vulnerable to CVE-2023-38646 ... The vulnerability allows an attacker to execute arbitrary commands on the server. The DreamBus exploit targeting the vulnerability is likely based on an open source proof-of-concept.
The attack, at its core, exploits a critical missing authentication bug (CVE-2023-48022, CVSS score: 9.8) to take control of susceptible instances and hijack their computing power for illicit cryptocurrency mining using XMRig.
CVE-2026-20182 carries a CVSSv3.1 score of 10.0 (Critical) and is classified under CWE-287: Improper Authentication. The flaw affects the Cisco Catalyst SD-WAN Controller (formerly vSmart)... The peering authentication mechanism is not functioning correctly, allowing an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on the affected system.
Apr 2024 PAN-OS CVE-2024-3400 exploit integration (Akamai)
Analysis of react.py This script is clearly set to exploit CVE-2025-29927, also known as React2Shell. ... This script implements a fully automated React/Next.js exploitation pipeline centered on abusing CVE-2025-29927 to achieve remote command execution at scale.
Malware campaigns include the Muhstik botnet and XMRig Monero Cryptocurrency mining. | Drupal versions before 7.58... allow remote attackers to execute arbitrary code... Malware campaigns include the Muhstik botnet and XMRig Monero Cryptocurrency mining.
The PoC repository contained a PDF file... downloading and running three files: Xsession.sh → The main malware script; xsession.auth → A disguised Monero miner (XMRig); xprintidle → A utility to detect when the system was idle. | Late at night, I was testing a proof-of-concept (PoC) exploit for CVE-2020-35489 ... The script appears to be a simple Proof-of-Concept (PoC) for an exploit, but in reality, it contains hidden malicious functionality.
“CoinMiner XMRig, a CoinMiner that mines the Monero cryptocurrency, was the one the most used in the attacks.”
"x522, which kills competing miners such as XMRig and Kinsing, and launches the miner with a c3pool.org configuration"
29 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TeamPCP a débuté par l’exploitation opportuniste d’infrastructures cloud exposées ... déployant XMRig pour le minage de Monero
the AhnLab SEcurity intelligence Center (ASEC) identified an instance in which the Larva-26009 threat actor installed the XMRig CoinMiner.
Il dépose entre 40 et 50 exécutables ... et installe simultanément plusieurs familles de malwares : XMRig v6.2.2 (minage Monero, pool pool.supportxmr.com:3333 )
The packages copied legitimate Ruby libraries and altered their entry-point files to launch mining code... Download URL raw.githubusercontent.com/xmrig/xmrig/v6.22.2/xmrig-6.22.2-linux-static-x64.tar.gz Miner archive download location
The packages copied legitimate Ruby libraries and altered their entry-point files to launch mining code... Download URL raw.githubusercontent.com/xmrig/xmrig/v6.22.2/xmrig-6.22.2-linux-static-x64.tar.gz Miner archive download location
Криптоджекинг (T1496, Resource Hijacking). Развёртывание XMRig - самый частый сценарий.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
A cron-based persistence attempt checked for the miner every 15 minutes, although logs indicate that this worked on relatively few targets.
When enabled, it looked for the prefix DLHELPER_CMD :, passed the remaining text to the system shell in a background thread, and allowed the command to run for up to 30 seconds.
It actively interacts with kernel MSR (Model-Specific Registers) and allocates Huge Pages to squeeze every ounce of processing power from the victim’s hardware, while utilizing a companion bash script to kill off competing processes.
The implant deletes its own binary from disk after execution, residing entirely in memory, which circumvents conventional disk scans.
the malware employs process masquerading, spoofing legitimate process names like "ssh"
The attackers also disable core logging services and tamper with authentication logs, leaving minimal traces of their actions.
565 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cryptocurrency mining malware/tool used to mine Monero on compromised Deluge and qBittorrent hosts.
Cryptominer deployed after compromising Deluge and qBittorrent instances to hijack compute resources for Monero mining.
Mentioned only in related-articles text, not part of the primary event.
Cryptominer deployed on exposed cloud infrastructure to mine Monero.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.