GhostMiner is a fileless cryptocurrency-mining malware family active since at least 2018 that primarily targets Windows systems. It is notable for abusing Windows Management Instrumentation (WMI) for persistence, payload storage, execution, and antivirus evasion, allowing it to operate with minimal conventional on-disk artifacts. GhostMiner has been observed storing Base64-encoded PowerShell content in WMI objects, triggering execution through WMI event subscriptions, and using reflective loading techniques to run malicious components in memory. Its primary monetization objective is cryptomining, including Monero mining, by deploying a miner payload and consuming victim CPU resources.
Beyond mining, GhostMiner exhibits post-compromise maintenance and competitive exclusion behavior commonly seen in illicit mining operations. It can terminate processes and services associated with rival miners, remove competing scheduled tasks and services, interfere with network activity linked to other mining malware, and alter host resolution behavior to disrupt competing botnets. It also includes backdoor-style command handling through encoded communications and can execute returned commands via PowerShell, indicating limited remote operator control in support of mining operations.
GhostMiner has been associated with server-side exploitation and worm-like propagation in some campaigns. Reported activity includes probing random internet-facing systems and exploiting Oracle WebLogic Server vulnerability CVE-2017-10271, while earlier reporting also linked GhostMiner campaigns to exploitation of exposed MSSQL and phpMyAdmin environments. The malware has been described as fileless PowerShell-based malware and as part of broader cryptomining botnet activity. Targeting has centered on susceptible Windows hosts and vulnerable servers rather than a specific vertical, with emphasis on systems that can provide sustained compute resources for mining.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
GhostMiner was a piece of technical art... probing random IP addresses and targeting them with an exploit for a certain 1-day vulnerability (in this case CVE-2017-10271, a vulnerability in Oracle’s WebLogic server). | Another example of Powershell malware was GhostMiner, a fileless threat discovered by researchers at Minerva at 2018 that used its hapless victims’ CPU cycles to mine cryptocurrency.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
GhostMiner ... weaponizes Windows management instrumentation (WMI) objects for its fileless persistence, payload mechanisms, and AV-evasion capabilities.
WMI_Killer function, which terminates running processes, and deletes scheduled tasks and services that are associated with cryptocurrency-mining malware families
GhostMiner uses WMI Event Subscriptions to install persistence in an infected machine as well as execute arbitrary code.
WMI_Killer function, which terminates running processes, and deletes scheduled tasks and services that are associated with cryptocurrency-mining malware families
WMI_Killer function, which terminates running processes, and deletes scheduled tasks and services that are associated with cryptocurrency-mining malware families
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced for historical comparison as an earlier botnet/miner whose scripts resemble LemonDuck's competition-removal behavior.
Fileless cryptocurrency-mining malware that abuses WMI for persistence, payload execution, and AV evasion. It installs WMI event subscriptions and a WMI class containing encoded command, backdoor, and miner components, communicates with C2 servers, drops and runs a Monero miner, and modifies hosts files while killing competing cryptomining malware.
A fileless PowerShell cryptomining threat that propagated by probing random IPs and exploiting Oracle WebLogic, then used reflective DLL loading and compression tooling for evasion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.