GMiner is a GPU-focused cryptocurrency mining program that has been deployed as a payload in cryptojacking operations. It has been observed in campaigns targeting Windows systems with high-performance discrete GPUs, including gamers, hardware enthusiasts, and AI users. In one such operation, victims were lured to fraudulent software-download sites through SEO poisoning and, in some cases, AI-generated software recommendations. The infection chain used DLL sideloading, abused ScreenConnect for persistent remote access, conducted host and GPU reconnaissance, and used process hollowing and security-tool exclusions before dynamically downloading a selected GPU miner, including GMiner. GMiner has also been downloaded by Linux-based cryptomining tooling when NVIDIA GPU hardware is detected. ShadowHS, a fileless Linux post-exploitation framework, includes GMiner among its optional CPU/GPU mining workflows. GMiner is legitimate mining software but is frequently abused by attackers to consume victim GPU resources for unauthorized cryptocurrency mining.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
Закрепившись в системе, вредонос собирал подробную информацию о зараженной машине
The malware also watches for analysis tools like Windows Task Manager, Process Hacker, and Process Explorer. The moment it detects any of them running, it immediately pauses mining to avoid suspicion.
Rather than embedding the miners directly into the malware, the payload dynamically downloaded the most appropriate mining software after conducting extensive reconnaissance on the victim system, including GPU model, CPU specifications, installed antivirus software, memory configuration, and overall system activity.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
gminer is one of the final GPU cryptocurrency mining payloads deployed in the campaign to mine cryptocurrency on victim systems.
GPU-focused cryptocurrency mining software deployed on compromised systems after reconnaissance to mine cryptocurrency while evading user detection.
Майнер криптовалют, использующий GPU зараженной системы для добычи криптовалюты.
A cryptocurrency mining program downloaded at runtime as part of the final-stage payload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.