XMRig is an open-source cryptocurrency miner primarily used to mine Monero, including through the RandomX proof-of-work algorithm. Although legitimate mining software, it is frequently deployed without authorization by threat actors after compromising systems, allowing them to consume victim CPU resources for mining revenue. Observed malicious deployments have targeted Windows, Linux, and macOS systems, including internet-exposed servers and AI or workflow infrastructure. Operators commonly configure XMRig to connect to Monero mining pools, may tune host CPU settings for RandomX performance, and can disguise the miner within plausible application or service contexts. XMRig is routinely delivered as a post-compromise payload alongside persistence, credential theft, reconnaissance, and other intrusion activity, but those surrounding capabilities are not inherent to XMRig itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
32 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2026-65400 (CVSS 9.8, CWE-287: Improper Authentication) — pre-auth уязвимость... Пароль не нужен... Apple закрыла в macOS Tahoe 26.6.1, Sequoia 15.7.9, Sonoma 14.8.9. CISA: SSVC «Act» — active exploitation, automatable, total technical impact.
CVE-2026-42271, command injection in test endpoints. For the second flaw, attackers submitted a fake MCP server configuration whose command field launched a Python downloader and cryptominer.
In the Kestra incident, attackers likely exploited CVE-2026-49869, a critical authentication-bypass flaw, to create a malicious workflow and make the worker run shell commands.
The LiteLLM attack path described in public research chains CVE-2026-42271 with CVE-2026-48710, a Starlette host-header validation bypass, to achieve unauthenticated remote code execution in vulnerable exposed deployments.
CISA and the FBI issued a joint advisory warning of ongoing exploitation of the Log4Shell vulnerability (CVE-2021-44228) on November 16. The advisory noted that an unspecified Iran-linked threat actor group had exploited the vulnerability during an intrusion into a Federal Civilian Executive Branch (FCEB) organization’s network earlier this year. | the affected victim server subsequently made a DNS query to us‐nation‐ny[.]cf... and then subsequently executed PowerShell commands enabling the threat actors to download and execute additional malicious files, including the XMRig crypto mining software.
The eSentire Security Operations Center (SOC) has observed active exploitation of Citrix vulnerability CVE-2019-19781 to deliver cryptocurrency mining malware to vulnerable systems... CVE-2019-19781 allows simple directory traversal by a remote attacker in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. No patches have been made available at this time. | Indicators of Compromise (Cryptocurrency Malware Campaign) ... hxxp: //217.12[.]221.12/netscalerd XMRig Cryptocurrency Miner
We have previously published a blog on what organizations need to know about the actively exploited CVE-2025-55182, which is a critical (CVSS 10.0) pre-authentication remote code execution vulnerability affecting React Server Components (RSC) used in React.js, Next.js, and related frameworks.
Cisco Talos also identified attacks targeting three additional vulnerabilities within Cisco Catalyst SD-WAN Manager, tracked as CVE-2026-20133 (CVSS: 7.5), CVE-2026-20128 (CVSS: 7.5), and CVE-2026-20122 (CVSS: 5.4). All three vulnerabilities were disclosed along with security patches in February 2026. | ...resulting in the deployment of webshell (Godzilla, Behinder, XenShell), Command-and-Control (C2) frameworks (AdaptixC2, Sliver), the XMRig coin miner...
Cisco Talos also identified attacks targeting three additional vulnerabilities within Cisco Catalyst SD-WAN Manager, tracked as CVE-2026-20133 (CVSS: 7.5), CVE-2026-20128 (CVSS: 7.5), and CVE-2026-20122 (CVSS: 5.4). All three vulnerabilities were disclosed along with security patches in February 2026. | ...resulting in the deployment of webshell (Godzilla, Behinder, XenShell), Command-and-Control (C2) frameworks (AdaptixC2, Sliver), the XMRig coin miner...
Cisco Talos also identified attacks targeting three additional vulnerabilities within Cisco Catalyst SD-WAN Manager, tracked as CVE-2026-20133 (CVSS: 7.5), CVE-2026-20128 (CVSS: 7.5), and CVE-2026-20122 (CVSS: 5.4). All three vulnerabilities were disclosed along with security patches in February 2026. | ...resulting in the deployment of webshell (Godzilla, Behinder, XenShell), Command-and-Control (C2) frameworks (AdaptixC2, Sliver), the XMRig coin miner...
CVEs : CVE-2024-23897 — NVD ... Le contenu décrit aussi RAGE ciblant des services exposés, dont Jenkins, pour déployer XMRig.
the threat actor took advantage of a WebLogic remote code execution vulnerability (CVE-2020–14882) to gain initial access to the system before installing a coin miner (XMRig).
Between February 28 and May 2, multiple exploitations of the CVE-2025-32432 were observed during our daily threat monitoring. This vulnerability is a Remote Code Execution affecting the Craft Content Management System.
On August 25, Atlassian publicly released a patch for a critical remote code execution vulnerability in its popular corporate wiki solution Confluence. Just days later, a proof of concept (POC) code demonstrating how to exploit this CVE was published to GitHub. As expected, threat actors rapidly began exploiting publicly facing Confluence servers. | IronNet observed what appeared to be a number of different botnets, in some cases pushing the same shell script but always ultimately leading to a XMRig coinminer.
The campaign exploits these recent vulnerabilities: CVE-2020-28188, CVE-2021-3007 and CVE-2020-7961. These allow the attacker to upload and execute a Python script on the compromised servers. CVE-2020-28188 The vulnerability is caused by a lack of input validation in the “event” parameter in the “makecvs” PHP page (/include/makecvs.php). This allows a remote unauthenticated attacker to inject OS commands, and gain control of the servers using TerraMaster TOS (versions prior to 4.2.06). | In the latest code downloaded (January 12, 2021), it seems that the malware tries to exploit the vulnerabilities to install the Xmrig from the server hxxp://gxbrowser[.]net.
On December 9, 2021, an RCE vulnerability was disclosed within the log4j package (CVE-2021-44228, CVE-2021-45046) which allows an attacker to execute arbitrary code on machines that utilize the logging functionality of the log4j package. | Case 1 - XMRig ... Xmrig.exe is part of XMRig open-source CPU/GPU cryptocurrency mining software ... The downloaded payload is XMRig miner.
CVE-2021-3007 This vulnerability is caused by the unsecured deserialization of an object. In versions higher than Zend Framework 3.0.0, the attacker abuses the Zend3 feature that loads classes from objects in order to upload and execute malicious code in the server. | In the latest code downloaded (January 12, 2021), it seems that the malware tries to exploit the vulnerabilities to install the Xmrig from the server hxxp://gxbrowser[.]net.
In May 2020, security vendors linked Kinsing to an additional campaign: one exploiting SaltStack CVE-2020-11651 and CVE-2020-11652.
CVE-2020-7961 The vulnerability is a Java unmarshalling vulnerability via JSONWS in Liferay Portal (in versions prior to 7.2.1 CE GA2). Exploiting the vulnerability lets the attacker provide a malicious object, that when unmarshalled, allows remote code execution. | In the latest code downloaded (January 12, 2021), it seems that the malware tries to exploit the vulnerabilities to install the Xmrig from the server hxxp://gxbrowser[.]net.
In May 2020, security vendors linked Kinsing to an additional campaign: one exploiting SaltStack CVE-2020-11651 and CVE-2020-11652.
Our Anglerfish honeypot system captured two propagation methods: one uses traditional telnet weak password and the other one utilizes an 1-day vulnerability (CVE-2020-35665)... The following is the payload when exploiting the 1-day vulnerability CVE-2020-35665.
The worm scans and exploits existing server based vulnerabilities like CVE-2020-14882 and CVE-2017-11610 from the victim machine... CVE-2017-11610 - A Remote Code Authentication (RCE) vulnerability in the XMLRPC interface in supervisord. | The worm deploys the embedded Xmrig miner to the /tmp location on the victim server... The miner disables the hardware prefetcher by using MSR to boost the mining process.
2. F5 BIG-IP (CVE-2020-5902 and CVE-2021-22986)
We observed attackers targeting the following package and products via security vulnerabilities disclosed in 2020 and 2021 for malicious cryptocurrency-mining activities through samples caught in our honeypots: 1. Atlassian Confluence (CVE-2021-26084 and CVE-2021-26085)
Drupal versions before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allow remote attackers to execute arbitrary code... Malware campaigns include the Muhstik botnet and XMRig Monero Cryptocurrency mining. | Malware campaigns include the Muhstik botnet and XMRig Monero Cryptocurrency mining.
360Netlab Threat Detection System started to report attacks targeting the widely used QNAP NAS devices via the unauthorized remote command execution vulnerability (CVE-2020-2506 & CVE-2020-2507), upon successful attack, the attacker will gain root privilege on the device and perform malicious mining activities.
5. Apache HTTP Server (CVE-2021-40438, CVE-2021-41773, and CVE-2021-42013)
3. VMware vCenter (CVE-2021-22005, CVE-2021-21985, CVE-2021-21972, and CVE-2021-21973)
2. F5 BIG-IP (CVE-2020-5902 and CVE-2021-22986)
3. VMware vCenter (CVE-2021-22005, CVE-2021-21985, CVE-2021-21972, and CVE-2021-21973)
3. VMware vCenter (CVE-2021-22005, CVE-2021-21985, CVE-2021-21972, and CVE-2021-21973)
360Netlab Threat Detection System started to report attacks targeting the widely used QNAP NAS devices via the unauthorized remote command execution vulnerability (CVE-2020-2506 & CVE-2020-2507), upon successful attack, the attacker will gain root privilege on the device and perform malicious mining activities.
46 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Revenus via minage XMRig (Monero), réseau proxy loué, et revente/extorsion de données volées.
the affected victim server subsequently made a DNS query to us‐nation‐ny[.]cf... and then subsequently executed PowerShell commands enabling the threat actors to download and execute additional malicious files, including the XMRig crypto mining software.
the affected victim server subsequently made a DNS query to us‐nation‐ny[.]cf... and then subsequently executed PowerShell commands enabling the threat actors to download and execute additional malicious files, including the XMRig crypto mining software.
RAGE est un framework Python personnalisé, généré avec l’aide de l’IA, ciblant des services exposés (...) pour déployer XMRig.
Blue Mockingbird has executed custom-compiled XMRIG miner DLLs using rundll32.exe.
The code shown below highlights how TeamTNT installed a cryptominer on the compromised pod running in the active node of the Kubernetes cluster. The module reflects how the xmrig.tgz file is downloaded and the cryptominer is installed on the compromised pod.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
"cron entries created" and a "crontab rewrite removed entries associated with other miner names."
The command field is passed directly to subprocess execution with no validation. Attackers submitted a fake MCP stdio server configuration where the command field contained a Python script that downloaded and executed a cryptominer.
The Windows payload invokes "powershell -w hidden" to download and run xmrig.exe. The unknown PE-family Java class also launches PowerShell with execution-policy bypass, hidden windowing, and an encoded command.
The downloaded payload executes via the macOS-native osascript command-line utility.
The clipboard command fetches a payload from a Cloudflare Worker using curl and executes it immediately in memory.
Commands arrive base64-encoded to bypass naive prompt-level filtering: echo ... | base64 -d | bash -i.
«Процесс sysmond с аномально высокой CPU-нагрузкой… вредоносный бинарник маскируется под него».
The downloaded ELF used service-style naming and arguments to masquerade as a benign Linux daemon; payloads were named after system daemons and launched with supervisord-style arguments.
The persistent backdoor agent polls the server every 60 seconds. The server returns instructions to download modular payloads on demand.
The content identifies raw-IP infrastructure on port 81 and sustained mining-pool connections as command-and-control activity.
1,275 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Криптомайнер, установленный на скомпрометированных macOS-хостах после эксплуатации CVE-2026-65400. Использует вычислительные ресурсы Mac для добычи Monero; вредоносный бинарник может маскироваться под системный процесс sysmond и закрепляться через LaunchDaemons.
Cryptomining tool used by TeamPCP to mine Monero on compromised hosts.
A Monero cryptominer deployed after compromise of exposed AI infrastructure, including Node-RED systems. Related activity used a miner staged under /tmp/.dbus-cache/gmon and connected to Monero mining infrastructure.
A cryptomining payload deployed on demand by the persistent macOS backdoor. The campaign removes its Gatekeeper quarantine attribute and uses it to mine Monero, producing high CPU usage and battery drain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.