SRBMiner-MULTI is a legitimate cryptocurrency-mining application that uses CPU and GPU resources. Its presence is not inherently malicious, but unauthorized deployment constitutes cryptojacking and can substantially degrade system performance and increase power consumption. It has been used as a GPU-mining payload in a Windows-focused cryptojacking operation targeting systems likely to have high-performance discrete GPUs, including gaming, hardware-enthusiast, and AI-development systems. In that operation, unidentified operators used poisoned search results and fraudulent software-download pages, including some links surfaced through AI-assisted software searches, to distribute trojanized utility downloads. The wider intrusion chain abused DLL sideloading, persistent remote-management access, process hollowing, security-tool exclusion changes, and analysis-tool detection before selecting and downloading a suitable miner. These surrounding persistence, remote-access, reconnaissance, and defense-evasion behaviors are attributed to the campaign’s supporting malware and operators rather than to SRBMiner-MULTI itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
“Ending a process stops that instance. It does not remove a scheduled task, service, startup entry, or another program capable of starting it again.”
The malware simplerunpe.exe invokes PowerShell to call the Add-MpPreference cmdlet, registering both path-based and process-based exclusions.
“Ending a process stops that instance. It does not remove a scheduled task, service, startup entry, or another program capable of starting it again.”
SimpleRunPE.exe does the heavy lifting from there... and uses process hollowing to inject mining code into a trusted Microsoft-signed binary.
Закрепившись в системе, вредонос собирал подробную информацию о зараженной машине
The malware also watches for analysis tools like Windows Task Manager, Process Hacker, and Process Explorer. The moment it detects any of them running, it immediately pauses mining to avoid suspicion.
Rather than embedding the miners directly into the malware, the payload dynamically downloaded the most appropriate mining software after conducting extensive reconnaissance on the victim system, including GPU model, CPU specifications, installed antivirus software, memory configuration, and overall system activity.
связывался с управляющим сервером и загружал один из майнеров — gminer, lolMiner или SRBMiner-MULTI
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A CPU- and GPU-based cryptocurrency miner. The content stresses that it is an established legitimate mining project, but it can be deployed without authorization and therefore warrants investigation when its installation, launcher, or configuration is unrecognized.
SRBMiner-MULTI is one of the final GPU cryptocurrency mining payloads deployed in the campaign to mine cryptocurrency on victim systems.
GPU-focused cryptocurrency mining software deployed on compromised systems after reconnaissance to mine cryptocurrency while evading user detection.
Майнер криптовалют, использующий GPU зараженной системы для добычи криптовалюты.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.