NBMiner is a legitimate cryptocurrency mining program that is also used maliciously as a cryptojacking payload. The provided content describes it being abused on industrial control system (ICS) computers, where attackers increasingly used PowerShell, fileless execution, and archives masquerading as legitimate software containing malicious LNK shortcut files to deploy miners. In ICS environments, security products may classify abused legitimate mining tools such as NBMiner as RiskTools rather than traditional malware. The content also links NBMiner to North Korea-linked activity tracked by ESET as DeceptiveDevelopment, also referred to as Contagious Interview and associated with the broader Lazarus umbrella. In those campaigns, software developers on Windows, Linux, and macOS—especially in cryptocurrency and Web3 projects—were targeted through fake recruiter approaches, trojanized coding challenges, and ClickFix-style fake interview lures. ESET reported that the group’s TsunamiKit/TsunamiClient .NET spyware component can drop cryptocurrency miners including XMRig and NBMiner. High-confidence behavior in the source material is limited to its use as a dropped miner/cryptojacking component and as a legitimate mining tool repurposed by threat actors; no specific standalone IOC set for NBMiner itself is provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
Threat actors are increasingly using PowerShell to execute malware, including crypto miners, by embedding malicious code directly into command line arguments.
The instructions provided by the phishing scripts tricked users into executing malicious PowerShell commands to download additional spyware... Nowadays, threat actors are increasingly using PowerShell to execute malware, including crypto miners, by embedding malicious code directly into command line arguments.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cryptocurrency miner dropped as a secondary payload by TsunamiClient.
Cryptocurrency miner dropped by TsunamiClient as part of TsunamiKit’s monetization/abuse chain.
Cryptocurrency miner delivered via a PowerShell dropper and an AutoIt loader; includes evasion (sleep/anti-sandbox), kills sigverif.exe, checks AV presence, and attempts UAC bypass via Fodhelper for silent elevation.
Legitimate cryptocurrency mining software abused by attackers on ICS computers, typically paired with customized configuration files to conceal mining activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.