Kingminer is an opportunistic Windows cryptomining botnet focused heavily on compromising exposed Microsoft SQL Server environments and deploying Monero-mining payloads. It is commonly associated with attacks against internet-facing MS-SQL servers that are weakly protected, including systems exposed to brute-force credential attacks or vulnerable to remote code execution. Reporting has also documented experimentation with EternalBlue-style propagation and possible use of local privilege-escalation exploits during infection.
The malware’s operational model centers on gaining execution through compromised SQL Server instances, then launching downloader and script-based stages that retrieve additional components from attacker-controlled infrastructure and public code-hosting services. Observed chains include sqlservr.exe spawning obfuscated VBScript or PowerShell, downloading architecture-specific payloads, and executing further stages filelessly in memory. Kingminer has used DLL side-loading with trusted signed executables, encrypted payload files, reflective or in-memory PE loading, and abuse of legitimate Windows binaries such as control.exe and rundll32.exe to launch miner components while reducing visibility.
Kingminer’s payload ecosystem includes customized use of public offensive and administrative tooling, including PowerSploit, Mimikatz, and XMRig-derived miners. Payload packages have been observed wrapped in XML containers holding compressed archives, with separate 32-bit and 64-bit variants. The miner itself has been described as a DLL-based XMRig variant used to mine Monero. The botnet also uses a time-based domain generation algorithm and multiple disposable GitHub accounts to rotate delivery infrastructure and host supporting components.
A notable feature of Kingminer is competitive suppression of other actors: it checks host operating-system versions and BlueKeep-related hotfixes, and on systems assessed as vulnerable it disables Remote Desktop access. This behavior appears intended to prevent rival botnets from exploiting the same host rather than to protect the victim. Repeated reinfection or redelivery attempts have been observed until the underlying exposed service or vulnerability was remediated.
Kingminer is best characterized as a criminal cryptojacking botnet targeting Windows servers, especially public-facing database infrastructure, using a mix of brute-force access, exploit-driven execution, fileless scripting, DLL side-loading, and defense-evasion techniques to establish and maintain illicit cryptocurrency mining.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
An opportunistic botnet that tries (not always successfully) to fly under the radar, Kingminer is nevertheless a persistent nuisance that delivers cryptocurrency miners as a payload.
An opportunistic botnet that tries (not always successfully) to fly under the radar, Kingminer is nevertheless a persistent nuisance that delivers cryptocurrency miners as a payload.
An opportunistic botnet that tries (not always successfully) to fly under the radar, Kingminer is nevertheless a persistent nuisance that delivers cryptocurrency miners as a payload.
An opportunistic botnet that tries (not always successfully) to fly under the radar, Kingminer is nevertheless a persistent nuisance that delivers cryptocurrency miners as a payload.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
A Microsoft SQL server process created an obfuscated PowerShell command... There are two commands here: One checks if the installed version of Windows is from Windows 2000 to Windows 7...
A Microsoft SQL server process created an obfuscated PowerShell command... The scripts are then executed filelessly using Invoke-Expression... sysdo.exe executing the following obfuscated commands directly to memory.
We observed a VBScript file named %PUBLIC%\gfghhjhyuq.vbs executed through sqlservr.exe... Despite the script being obfuscated, we were able to uncover most of its functions by decoding the hex string parameters.
The Managed XDR team addressed a Kingminer botnet attack conducted through an SQL exploit... We observed a VBScript file named %PUBLIC%\gfghhjhyuq.vbs executed through sqlservr.exe. This led us to suspect that the device had been exploited through a vulnerability that allowed malicious actors to execute arbitrary codes remotely.
Despite the script being obfuscated, we were able to uncover most of its functions by decoding the hex string parameters... sysdo.exe executing the following obfuscated commands directly to memory.
Once the attacker gains access to the admin account and logs into the server...
Finally, it runs a cryptocurrency miner payload through a Control Panel item... sysdo.exe invoked rundll32 using a main.cpl... The malicious actor used this module to launch the payload directly onto the device’s memory.
The botnet’s operators prefer to use open source or public domain software (like PowerSploit or Mimikatz )... This is where they store files like... the Mimikatz password stealer.
It then proceeds to download a 32-bit or 64-bit payload depending on the installed Windows version... Next, it downloads a standalone PowerShell binary from a raw file stored in a GitHub user’s repository... connects to http://ww[.]3113cfdae.com/eb[.]txt ... to download additional components.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a known miner family whose attack techniques may resemble those used to deploy MrbMiner.
A cryptomining botnet that brute-forces SQL server credentials, experiments with EternalBlue for propagation, uses privilege-escalation exploits and DLL side-loading, leverages public tools like Mimikatz and PowerSploit, and deploys XMRig-based miners to mine Monero.
CoinMiner operation that brute-forces exposed MS-SQL servers to gain execution and deploy mining payloads.
Kingminer is a botnet-associated cryptomining malware observed targeting Microsoft SQL servers via exploitation of exposed/unpatched services. In this intrusion chain, it uses an obfuscated VBScript executed by sqlservr.exe to stage a standalone PowerShell binary (renamed to sysdo.exe), pulls additional PowerShell scripts for fileless execution (Invoke-Expression), and ultimately runs a miner payload (including via Control Panel main.cpl/rundll32 abuse) while contacting attacker-controlled domains to retrieve components.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.