lolMiner
lolMiner is a legitimate GPU-focused cryptocurrency mining program that has been observed abused as a payload in multiple illicit cryptomining operations. In the provided reporting, it is repeatedly identified as one of several miners dynamically deployed after host compromise, alongside gminer and SRBMiner-MULTI, and in some campaigns is used specifically to mine Conflux while XMRig mines Monero.
Microsoft-linked reporting describes lolMiner being delivered in an active 2026 cryptojacking campaign that used more than 150 fake software download sites impersonating utilities such as CrystalDiskInfo, HWMonitor, Display Driver Uninstaller, FurMark, K-Lite Codec Pack, and PDFgear. Victims downloaded ZIP archives containing a legitimate executable and a malicious autorun.dll used for DLL sideloading. The infection chain installed ScreenConnect for persistent remote access, then deployed SimpleRunPE.exe, which established persistence via Registry Run keys, scheduled tasks, and Startup artifacts, added Microsoft Defender exclusions, performed anti-analysis checks, and used process hollowing into trusted Microsoft-signed .NET binaries such as InstallUtil.exe, RegAsm.exe, RegSvcs.exe, MSBuild.exe, AppLaunch.exe, AddInProcess.exe, and aspnet_compiler.exe. After profiling the victim system, the malware contacted attacker infrastructure and downloaded one of the supported GPU miners, including lolMiner. The campaign targeted users likely to own powerful discrete GPUs, including gamers, hardware enthusiasts, and AI developers, and Microsoft warned that the ScreenConnect foothold could also support data theft, lateral movement, and ransomware deployment.
High-confidence infrastructure and artifacts associated with that campaign include gleeze[.]com subdomains, WebSocket C2 wss://minemine.gleeze[.]com:8443/ws, attacker-controlled server 193.42.11[.]108, related IPs 93.115[.]10.35, 198.23[.]185.238, and 2.59.132[.]106, and files such as autorun.dll, vcredist_x64.dll, SimpleRunPE.exe, RuntimeHost.exe, and vlc.exe. Defender exclusion entries explicitly referenced lolMiner.exe, SRBMiner-MULTI.exe, miner.exe, and gminer.exe. The malware also monitored for analysis tools including Task Manager, Process Explorer, Process Hacker, System Informer, dnSpy, x64dbg, IDA, Ghidra, ProcMon, Wireshark, and Fiddler, and paused or terminated mining activity when such tools were detected.
Separate reporting ties lolMiner to attacks against Internet-exposed ComfyUI instances. In that campaign, attackers exploited unauthenticated or unsafe ComfyUI deployments via custom nodes and ComfyUI-Manager to achieve remote code execution, then deployed a shell payload known as ghost.sh. Compromised hosts were enrolled into a cryptomining and proxy botnet, with XMRig used for Monero mining and lolMiner used for Conflux mining, alongside Hysteria v2 proxy functionality. Reported infrastructure included 77.110.96.200, mining pools xmr.kryptex.network:8029 and cfx.kryptex.network:8027, Monero wallet 4BBj3gj4oV7iRikNHDgtETDFRm8Z6kG7diVMo8mDz4zcUiXogiF8chHRKK1THWW43zc8XbGYLfU4rbgeyWYaGpWG4ePiGt4, and Conflux wallet cfx:aaj5xbzcjukme1942fhgxsrxtnf92x7j3adxwu9sns. Persistence and evasion in that campaign included memfd_create-based fileless execution, /dev/shm fallback, an LD_PRELOAD rootkit, watchdog restoration, scattered backups, immutable file flags via chattr +i, and anti-competition logic.
The content also associates lolMiner with TeamTNT activity and with the ShadowHS Linux intrusion framework. TeamTNT is described as using lolMiner, RainbowMiner, and XMRig in cloud, container, Docker, and Kubernetes-focused cryptomining operations. ShadowHS is described as implementing CPU and GPU mining workflows including XMRig, XMR-Stak, GMiner, and lolMiner, with pool failover logic, alongside credential theft, lateral movement, and covert exfiltration capabilities.
Overall, based on the provided content, lolMiner should be understood not as bespoke malware but as a legitimate GPU miner frequently repurposed by threat actors as a final-stage payload in financially motivated cryptojacking campaigns targeting high-performance systems, Linux/cloud workloads, containers, and exposed AI infrastructure.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
12 distinct techniques documented for this family, organized by ATT&CK tactic.
Resource Development
1 technique
Resource Development
Initial Access
1 technique
Initial Access
Persistence
1 technique
Persistence
Privilege Escalation
1 technique
Privilege Escalation
Stealth
3 techniques
Stealth
SimpleRunPE.exe does the heavy lifting from there... and uses process hollowing to inject mining code into a trusted Microsoft-signed binary.
Defense Impairment
1 technique
Defense Impairment
Discovery
3 techniques
Discovery
Закрепившись в системе, вредонос собирал подробную информацию о зараженной машине
The malware also watches for analysis tools like Windows Task Manager, Process Hacker, and Process Explorer. The moment it detects any of them running, it immediately pauses mining to avoid suspicion.
Rather than embedding the miners directly into the malware, the payload dynamically downloaded the most appropriate mining software after conducting extensive reconnaissance on the victim system, including GPU model, CPU specifications, installed antivirus software, memory configuration, and overall system activity.
Command and Control
2 techniques
Command and Control
Impact
1 technique
Impact
IOCs tracked for this family
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
Recent activity
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
lolMiner is one of the final GPU cryptocurrency mining payloads deployed in the campaign to mine cryptocurrency on victim systems.
GPU-focused cryptocurrency mining software deployed on compromised systems after reconnaissance to mine cryptocurrency while evading user detection.
Майнер криптовалют, использующий GPU зараженной системы для добычи криптовалюты.
A cryptocurrency mining program downloaded at runtime as part of the final-stage payload.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.