cpuminer is a cryptocurrency-mining program that has been repeatedly repurposed in malicious cryptojacking operations to hijack victim compute resources for illicit mining. In observed abuse cases, operators delivered UPX-packed cpuminer payloads to compromised systems and executed them through pre-existing backdoors or webshell-like access on internet-exposed servers. The malware’s role in these intrusions is to consume CPU resources for mining rather than to provide full remote administration, but its deployment commonly occurs after an attacker has already obtained command execution on the host.
cpuminer has been associated with campaigns targeting Linux-based web infrastructure, including incidents affecting U.S. education organizations in 2021. In those cases, attackers issued malicious HTTP requests that appeared to invoke operating-system commands through a backdoor, then downloaded and launched the miner and, in some incidents, an additional lightweight shell for continued access. Broader reporting also links CPUMiner/EternalMiner to exploitation of the SambaCry vulnerability, showing that cpuminer-branded mining operations have been used in opportunistic exploitation campaigns that convert compromised devices into cryptocurrency-mining botnets.
As abused in the wild, cpuminer’s primary effect is unauthorized cryptocurrency mining and the resulting degradation of system performance, increased resource consumption, and operational impact on victim environments. Its presence can also indicate a wider compromise because miners are often deployed alongside backdoors, webshells, or other attacker tooling used for persistence and post-exploitation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cryptomining malware/tooling detected during ClamAV scanning examples; included as an example of custom rule hits rather than the main subject of the presentation.
Cryptocurrency-mining malware that exploited Samba vulnerabilities and turned infected devices into monero-mining botnets.
A malicious cryptominer payload used for cryptojacking. It is delivered via a backdoor/webshell and executes cryptocurrency mining using attacker-supplied parameters and wallet addresses.
in operations such as the ones that distributed CPUMINER, BankBot, and MilkyDoor, they would try to get their apps published on Google Play or App Store
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.