XMRig is an open-source cryptocurrency mining program primarily used to mine Monero and other RandomX or CryptoNight-family coins. Although legitimate in benign mining contexts, it is widely abused by threat actors as a cryptomining payload after host compromise. Intrusions involving XMRig commonly follow exploitation of internet-facing services, brute-force or credential-based access to Linux SSH servers, SQL injection against web applications, supply-chain compromise, downloader-based malware chains, and malvertising campaigns that bundle XMRig with other payloads such as Vidar. It has also been deployed after exploitation of enterprise software vulnerabilities, including GitLab and TeamCity-related attack chains, and in cloud compromises affecting exposed EC2 instances.
In malicious operations, XMRig is typically used for resource hijacking and monetization through unauthorized mining. Threat actors often deliver it through loaders, downloaders, trojans, botnets, or propagation malware rather than relying on XMRig alone as the initial intrusion tool. Observed campaigns have included Windows and Linux infections, with Linux-focused activity frequently using SSH scanning, brute-force, and worm-like propagation to spread miners across poorly managed servers. On Windows, XMRig has appeared in campaigns using fake cracked-software lures, DLL sideloading, hidden PowerShell staging, scheduled tasks, service-based persistence, and file-hiding techniques. On Linux, customized variants have used disguised process names, watchdog behavior, cron jobs, and systemd services to maintain execution and restore deleted miner components.
XMRig is frequently paired with defense-evasion and persistence mechanisms added by operators or wrapper malware. These include process masquerading, hidden or renamed binaries, lock files, watchdog components, startup persistence, scheduled execution, and service installation. Some actor-modified builds embed mining configuration internally or are launched through helper tools that alter visible process names. XMRig has also been incorporated into broader malware ecosystems associated with botnets and financially motivated intrusion sets, including Sysrv-related activity, Phorpiex-linked campaigns, Vidar affiliate operations, and Linux server compromises involving ShellBot, MIG LogCleaner, and XHide.
Targets are opportunistic and broad, including consumers, SMBs, software developers, Linux server operators, CI/CD infrastructure, web servers, and cloud workloads. In many incidents, XMRig is not the sole objective but part of a dual-monetization model alongside credential theft, spyware, or remote access tooling. Its prevalence in post-compromise activity makes it a common indicator of unauthorized resource consumption and broader host compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
26 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2021-22205 is a critical remote code execution vulnerability in the service’s web interface... GitLab amended the CVSSv3 score to 10.0... shifting the vulnerability from an authenticated to an unauthenticated condition... The entry point for this vulnerability is the POST request via /uploads/user endpoint.
APT29 (Cozy Bear) exploited CVE-2024-27198 in real-world campaigns.
In this case, the attacker was automatically trying to exploit CVE-2024-4577, which affects certain versions of PHP 8 when using Apache and PHP-CGI on Windows.
Threat actors are continuing to exploit a critical Langflow vulnerability as part of fresh attacks designed to deliver a Monero cryptocurrency miner. The activity has been found to weaponize CVE-2026-33017 (CVSS score: 9.3), an unauthenticated remote code execution (RCE) vulnerability in Langflow, indicating threat actors are scanning and targeting exposed artificial intelligence (AI) application endpoints for obtaining initial access to enterprise networks.
The React2Shell vulnerability (CVE-2025–55182) was reported to the React team on November 29. Public advisories and patches dropped on December 3. Threat actors started exploiting it within hours... React2Shell (CVE-2025–55182) is a critical, unauthenticated remote code execution bug in React Server Components’ “Flight” protocol. | Common post-exploitation moves: Install XMRig or another cryptominer
Along with patching, we recommend examining SAP web server access logs for additional evidence of CVE-2025-31324 exploitation, specifically looking for evidence of unusual requests to the API endpoint /developmentserver/metadatauploader . If possible, consider disallowing access to that API endpoint from external networks. To hunt for additional evidence of web shell uploads, organizations can search for unexpected JSP files within these folders on SAP servers... | hxxp[://]23.95.123[.]5:666/xmrigCCall/8bq.sh
This service is accompanied by a pipe named \\.\WinRing0_1_2_0 which allows the process to communicate with the driver. This is quite an old driver, vulnerable to CVE-2020-14979 and CVE-2021-41285, and allowing the actor to elevate privileges to NT\SYSTEM as soon as the direct unchecked communication with the driver is allowed and the attacker controls input forwarded to the driver.
This service is accompanied by a pipe named \\.\WinRing0_1_2_0 which allows the process to communicate with the driver. This is quite an old driver, vulnerable to CVE-2020-14979 and CVE-2021-41285, and allowing the actor to elevate privileges to NT\SYSTEM as soon as the direct unchecked communication with the driver is allowed and the attacker controls input forwarded to the driver.
Ahnlab Security Emergency response Center (ASEC) has recently confirmed that the 8220 Gang attack group is using the Log4Shell vulnerability to install CoinMiner in VMware Horizon servers. Log4Shell (CVE-2021-44228) is both a remote code execution vulnerability and the Java-based logging utility Log4j vulnerability... | If the CVE-2022-26134 vulnerability attack succeeds, the following PowerShell command downloads and executes additional PowerShell scripts and ultimately installs XMRig CoinMiner.
The group targets not only global systems but also Korean ones. ASEC has introduced a case where the attack group abused the Atlassian Confluence server vulnerability CVE-2022-26134 to attack Korean systems and install CoinMiner. | If the CVE-2022-26134 vulnerability attack succeeds, the following PowerShell command downloads and executes additional PowerShell scripts and ultimately installs XMRig CoinMiner.
In this cluster of activity, since at least March 25, 2026, an XMRig sample and its accompanying configuration file were downloaded and deployed via a shell script.
In this cluster of activity, since at least March 25, 2026, an XMRig sample and its accompanying configuration file were downloaded and deployed via a shell script.
In this cluster of activity, since at least March 25, 2026, an XMRig sample and its accompanying configuration file were downloaded and deployed via a shell script.
Several devices initiated TCP connections to endpoints affiliated with cryptomining pools such as us[.]zephyr[.]herominers[.]com and xmrig[.]com. Connectivity to these domains indicates likely successful installation of mining software during earlier stages of post-compromise activity.
Several devices initiated TCP connections to endpoints affiliated with cryptomining pools such as us[.]zephyr[.]herominers[.]com and xmrig[.]com. Connectivity to these domains indicates likely successful installation of mining software during earlier stages of post-compromise activity.
CVE-2022-22954, a remote code execution (RCE) vulnerability due to server-side template injection in VMware Workspace ONE Access and Identity Manager, is trivial to exploit with a single HTTP request to a vulnerable device.
Apache RocketMQ Exploit Module (CVE-2023-33246) ... In June 2023, a vulnerability cataloged as CVE-2023-33246 was discovered that enables an attacker to achieve remote command execution (RCE) on RocketMQ versions 5.1.0 and earlier. Shortly after, DreamBus added an exploit module to target this vulnerability.
Metabase Exploit Module (CVE-2023-38646) ... The open source versions of Metabase 0.46.6.1 and earlier, as well as Metabase Enterprise 1.46.6.1 and earlier, are vulnerable to CVE-2023-38646 ... The vulnerability allows an attacker to execute arbitrary commands on the server. The DreamBus exploit targeting the vulnerability is likely based on an open source proof-of-concept.
The attack, at its core, exploits a critical missing authentication bug (CVE-2023-48022, CVSS score: 9.8) to take control of susceptible instances and hijack their computing power for illicit cryptocurrency mining using XMRig.
CVE-2026-20182 carries a CVSSv3.1 score of 10.0 (Critical) and is classified under CWE-287: Improper Authentication. The flaw affects the Cisco Catalyst SD-WAN Controller (formerly vSmart)... The peering authentication mechanism is not functioning correctly, allowing an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on the affected system.
Apr 2024 PAN-OS CVE-2024-3400 exploit integration (Akamai)
Analysis of react.py This script is clearly set to exploit CVE-2025-29927, also known as React2Shell. ... This script implements a fully automated React/Next.js exploitation pipeline centered on abusing CVE-2025-29927 to achieve remote command execution at scale.
Malware campaigns include the Muhstik botnet and XMRig Monero Cryptocurrency mining. | Drupal versions before 7.58... allow remote attackers to execute arbitrary code... Malware campaigns include the Muhstik botnet and XMRig Monero Cryptocurrency mining.
The PoC repository contained a PDF file... downloading and running three files: Xsession.sh → The main malware script; xsession.auth → A disguised Monero miner (XMRig); xprintidle → A utility to detect when the system was idle. | Late at night, I was testing a proof-of-concept (PoC) exploit for CVE-2020-35489 ... The script appears to be a simple Proof-of-Concept (PoC) for an exploit, but in reality, it contains hidden malicious functionality.
“CoinMiner XMRig, a CoinMiner that mines the Monero cryptocurrency, was the one the most used in the attacks.”
"x522, which kills competing miners such as XMRig and Kinsing, and launches the miner with a c3pool.org configuration"
23 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The observed tactics, targeting, and tradecraft closely align with the Rare Werewolf (Librarian Ghouls) threat actor, although no XMRig cryptomining activity was observed in this sample.
The observed tactics, targeting, and tradecraft closely align with the Rare Werewolf (Librarian Ghouls) threat actor, although no XMRig cryptomining activity was observed in this sample.
Blue Mockingbird has made their XMRIG payloads persistent as a Windows Service.
By querying the hash on threat intelligence portals and by statically analyzing the sample, it became clear that this binary is a malicious modified version of XMRig (6.19.0), a cryptocurrency miner.
One of the campaigns deployed an XMRig cryptocurrency miner on a small number of infected machines, which is not standard behavior for a disciplined intelligence operation.
Impact T1496 Resource Hijacking TeamPCP kills competing XMRig cryptominers before deploying own payloads
27 distinct techniques documented for this family, organized by ATT&CK tactic.
the activity appears to follow a sequence often seen in compromises of internet-facing systems: brute-forced access, payload delivery, and repeated outbound connectivity to mining pool infrastructure.
Stage 1: Internet-exposed SSH enabled initial access ... the LiteLLM-Proxy EC2 instance appeared to be externally exposed over SSH, with port 22 open to 0.0.0.0/0.
Scheduled task : schtasks /create /tn "SystemAgentService" /tr "NisSrv.exe -s" /sc onlogon /f
the EC2 instance downloaded 3.42 MB of data over an HTTP connection on port 80 to the external endpoint, 185.62.1[.]8, which appears to host a ZIP file containing XMRig crypto-mining malware.
Scheduled task : schtasks /create /tn "SystemAgentService" /tr "NisSrv.exe -s" /sc onlogon /f
the activity appears to follow a sequence often seen in compromises of internet-facing systems: brute-forced access, payload delivery, and repeated outbound connectivity to mining pool infrastructure.
Scheduled task : schtasks /create /tn "SystemAgentService" /tr "NisSrv.exe -s" /sc onlogon /f
Both the DLL name and function name are XOR-obfuscated with single-byte key 0x05 to evade static string scanning.
Those two files with modified characteristics ( edge.exe and Taskgmr.ps1 ) were sitting in C:\Program Files (x86)\Microsoft\EdgeUpdate\ .
The maps table shows the binary that initiated the process, then it has been deleted... the malware often self-deleted itself.
the activity appears to follow a sequence often seen in compromises of internet-facing systems: brute-forced access, payload delivery, and repeated outbound connectivity to mining pool infrastructure.
Loaders in Clusters A and C append hundreds of megabytes of null bytes after the last PE section... Most automated sandbox environments enforce an upper file-size limit of 50-100 MB and silently skip oversized submissions.
Geolocation beacon : GET request to ip-api[.]com/json resolves the victim's public IP address and country, which are embedded in the subsequent Telegram alert
Meta scanned SSH ports and attempted further infections using information from the ranges and pass files.
513 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Open-source miner deployed by the trojan on idle machines for rogue cryptocurrency mining.
A coin-mining payload installed on poorly managed Linux SSH servers by propagation-capable malware.
XMRig is deployed here as a malicious Monero miner payload. The malware downloads and executes it with attacker-controlled pool and wallet parameters, turning the victim host into a cryptocurrency mining bot while limiting CPU usage to reduce suspicion.
Mining software used as the basis for a separate cryptocurrency-mining component deployed by the Siggen backdoor on compromised devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.