XMRigCC is a Monero cryptocurrency mining malware derived from the open-source XMRigCC project and widely used in illicit cryptomining operations. It has been deployed by multiple financially motivated threat actors, including activity associated with the Tor2Mine ecosystem, and is commonly installed after initial compromise as a monetization payload on Windows systems.
Observed intrusions show XMRigCC delivered through PowerShell-based loader chains, post-exploitation tooling, and broader multi-payload campaigns. It has appeared in operations involving brute-force compromise of internet-facing Microsoft SQL Server instances, as well as campaigns using archive-delivered disk images and executable droppers that launch obfuscated PowerShell downloaders. In these cases, the malware is installed alongside persistence mechanisms such as scheduled tasks, Windows services, and registry-based autoruns.
Operationally, XMRigCC functions as a cryptominer that connects to attacker-selected mining infrastructure to mine Monero on compromised hosts. Associated loaders and deployment scripts frequently perform defense-evasion actions before or during miner installation, including disabling or weakening Microsoft Defender and attempting to stop or remove third-party security products. Some observed chains also deploy auxiliary components for persistence and may install a kernel driver associated with low-level hardware access. In several campaigns, XMRigCC was only one component of a larger monetization toolkit that also included remote-access malware, credential theft tooling, and clipboard-based cryptocurrency theft.
XMRigCC has been observed in enterprise intrusions affecting organizations such as telecommunications and consulting environments, and in ransomware-adjacent incidents where cryptomining tooling was deployed before later-stage destructive or extortion activity. Its repeated use across unrelated campaigns reflects its value as a readily adaptable mining payload for financially motivated operators targeting Windows environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
It then creates a scheduled task with the name OneDrive SyncTask to execute hourly and launch the miner which is read from the previously created registry entry.
It’s using Redis’s FLUSHALL issue to create a cron job that downloads a setup script... The cron job seen added in the same figure executes the upload script every five minutes.
It then creates a scheduled task with the name OneDrive SyncTask to execute hourly and launch the miner which is read from the previously created registry entry.
It’s using Redis’s FLUSHALL issue to create a cron job that downloads a setup script... The cron job seen added in the same figure executes the upload script every five minutes.
The script ensures the processes are started again if the machine is rebooted. The script adds either a System V init script or a systemd service depending on what is used by the system. | The script adds either a System V init script or a systemd service depending on what is used by the system.
It then creates a scheduled task with the name OneDrive SyncTask to execute hourly and launch the miner which is read from the previously created registry entry.
It’s using Redis’s FLUSHALL issue to create a cron job that downloads a setup script... The cron job seen added in the same figure executes the upload script every five minutes.
The script ensures the processes are started again if the machine is rebooted. The script adds either a System V init script or a systemd service depending on what is used by the system. | The script adds either a System V init script or a systemd service depending on what is used by the system.
It lets you control your miners via a Dashboard or the REST api. | XMRigCC has a "Command and Control" (CC) server part, a daemon to keep the XMRigCC miner alive and modifications to send the current status to the CC Server.
85 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as the mining software base underlying Tor2Mine.
Variant of XMRig mentioned as infrastructure overlap/background context rather than a primary malware focus of the report.
Monero cryptocurrency miner based on an open-source miner controllable through a C2 console. In this campaign it is installed persistently via registry, scheduled tasks, services, and HTA/PowerShell loaders, and attempts to disable security tools.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.