Coinhive was a JavaScript-based Monero mining service and browser miner widely used for in-browser cryptomining. It enabled website operators or intruders to execute mining code in visitors’ browsers and consume local CPU resources to generate cryptocurrency. At its peak, it became one of the most recognizable components of the cryptojacking ecosystem and was frequently embedded into compromised websites, browser extensions, malicious advertisements, and web content modified after server compromise.
Coinhive was used both in nominally consensual monetization experiments and in unauthorized cryptojacking operations. Malvertising campaigns embedded Coinhive mining code inside advertisements served through legitimate high-traffic sites, covertly driving substantial CPU utilization on victim systems. It was also injected into webpages by other malware after compromising Linux web servers, allowing attackers to monetize both the server and its visitors. Reporting also documented Coinhive embedded in browser extensions and on compromised or intentionally modified websites.
Operationally, Coinhive functioned as a web miner rather than a traditional standalone implant. Its primary behavior was unauthorized cryptocurrency mining through browser-executed JavaScript, resulting in resource abuse and degraded performance on affected endpoints. In observed campaigns, it was commonly associated with cryptojacking activity rather than credential theft, persistence on endpoints, or destructive effects. Coinhive was also reused and modified by other actors, including private miner variants derived from its codebase.
Coinhive primarily targeted systems capable of running modern web browsers, and it also appeared on Linux web servers when injected into hosted HTML content by server-side malware. It was prominent across broad opportunistic campaigns rather than being exclusive to a single threat actor or sector, affecting general web users and organizations whose websites or infrastructure were abused for mining.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Browser-based cryptocurrency mining malware embedded in malicious advertisements. It covertly uses victims' CPU resources for mining, in this case configured to consume about 80% of CPU and distributed via abused DoubleClick ads on legitimate high-traffic sites.
Browser-based JavaScript cryptomining tool historically abused for cryptojacking (unauthorized Monero mining in victims’ browsers).
Monero mining component used as a payload by Linux Rabbit/Rabbot, including browser-based mining via injected script tags/JavaScript into HTML pages (notably on ARM/MIPS targets and compromised web servers).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.