lolMiner is a legitimate GPU-focused cryptocurrency mining program that is frequently repurposed by threat actors for illicit cryptojacking operations. It has been observed as a final mining payload in multi-stage intrusion chains on both Windows and Linux systems, where attackers first gain execution through methods such as fake software download sites, DLL sideloading, malicious scripts, exploitation of exposed services, or abuse of cloud and container infrastructure, and then deploy lolMiner to monetize victim compute resources. In criminal campaigns, lolMiner is commonly paired with other miners such as XMRig, GMiner, or SRBMiner-MULTI, with operators selecting the miner based on available hardware and target cryptocurrency.
On Windows, lolMiner has been deployed in campaigns that impersonate popular PC utilities and target users likely to own high-performance discrete GPUs, including gamers, hardware enthusiasts, and AI users. These operations have used malicious archives containing legitimate software plus a sideloaded DLL, followed by installation of persistent remote-access tooling and a loader that establishes persistence, adds security-tool exclusions, performs host reconnaissance, and injects or hollows trusted processes before downloading the miner. Operators have also delivered lolMiner through malicious PDF-driven infection chains and script-based loaders.
On Linux and cloud-native targets, lolMiner has been used after exploitation of exposed or misconfigured services, including containerized and AI-related infrastructure. Observed campaigns have used custom scanners and remote code execution paths to compromise Internet-exposed systems, then deploy lolMiner for GPU mining while also establishing persistence, anti-forensics measures, watchdogs, and in some cases proxy-botnet functionality. TeamTNT and other financially motivated actors have also used lolMiner in cloud and container intrusions alongside credential harvesting and broader resource hijacking activity.
When abused maliciously, lolMiner contributes to unauthorized cryptocurrency mining, resource exhaustion, and operational degradation, especially on GPU-capable hosts. In these contexts it is typically one component of a broader post-compromise framework that may include reconnaissance, persistence, defense evasion, remote access, and additional monetization or follow-on intrusion capabilities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
SimpleRunPE.exe does the heavy lifting from there... and uses process hollowing to inject mining code into a trusted Microsoft-signed binary.
Закрепившись в системе, вредонос собирал подробную информацию о зараженной машине
The malware also watches for analysis tools like Windows Task Manager, Process Hacker, and Process Explorer. The moment it detects any of them running, it immediately pauses mining to avoid suspicion.
Rather than embedding the miners directly into the malware, the payload dynamically downloaded the most appropriate mining software after conducting extensive reconnaissance on the victim system, including GPU model, CPU specifications, installed antivirus software, memory configuration, and overall system activity.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
lolMiner is one of the final GPU cryptocurrency mining payloads deployed in the campaign to mine cryptocurrency on victim systems.
GPU-focused cryptocurrency mining software deployed on compromised systems after reconnaissance to mine cryptocurrency while evading user detection.
Майнер криптовалют, использующий GPU зараженной системы для добычи криптовалюты.
A cryptocurrency mining program downloaded at runtime as part of the final-stage payload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.