UnityMiner is a Linux-based cryptomining malware toolkit used to hijack QNAP network-attached storage devices for Monero mining. It was identified in campaigns exploiting QNAP Helpdesk-related remote command execution vulnerabilities, including CVE-2020-2506 and CVE-2020-2507, which allowed attackers to obtain root privileges on exposed NAS systems and deploy the miner.
The malware is built around a modified XMRig component and includes installer and persistence scripts tailored for QNAP environments. Its installer determines device architecture, deploys the appropriate payload, adjusts mining configuration to limit CPU consumption, and establishes persistence through scheduled task execution. A companion watchdog script ensures the miner is restarted if it stops.
A notable feature of UnityMiner is its tampering with the QNAP administrative interface to conceal mining activity. It replaces a management CGI component with a forged version that suppresses visibility of the mining process and falsifies reported CPU utilization, reducing the likelihood that administrators will notice abnormal resource consumption. This combination of persistence, stealth, and resource abuse distinguishes it from simpler opportunistic miners.
UnityMiner is associated with opportunistic exploitation of internet-exposed QNAP NAS devices rather than broad multi-platform distribution. It has been documented as part of the wider threat landscape affecting NAS appliances, alongside ransomware, botnets, and backdoor malware that target under-hardened or unpatched storage systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
360Netlab Threat Detection System started to report attacks targeting the widely used QNAP NAS devices via the unauthorized remote command execution vulnerability (CVE-2020-2506 & CVE-2020-2507), upon successful attack, the attacker will gain root privilege on the device and perform malicious mining activities. | We named the mining program UnityMiner, we noticed the attacker customized the program by hiding the mining process and the real CPU memory resource usage information...
360Netlab Threat Detection System started to report attacks targeting the widely used QNAP NAS devices via the unauthorized remote command execution vulnerability (CVE-2020-2506 & CVE-2020-2507), upon successful attack, the attacker will gain root privilege on the device and perform malicious mining activities. | We named the mining program UnityMiner, we noticed the attacker customized the program by hiding the mining process and the real CPU memory resource usage information...
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Unpack the mining program, set cron and execute the mining script start.sh (once every minute, time interval is set directly to * * * * * * )
The mining program consists of unity_install.sh and Quick.tar.gz. unity_install.sh is used to download & set up & start the mining program...
360Netlab Threat Detection System started to report attacks targeting the widely used QNAP NAS devices via the unauthorized remote command execution vulnerability (CVE-2020-2506 & CVE-2020-2507), upon successful attack, the attacker will gain root privilege on the device and perform malicious mining activities.
the attacker customized the program by hiding the mining process and the real CPU memory resource usage information, so when the QNAP users check the system usage via the WEB management interface, they cannot see the abnormal system behavior.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cryptominer malware historically observed targeting QNAP NAS devices.
A cryptomining malware targeting vulnerable QNAP NAS devices via CVE-2020-2506 and CVE-2020-2507. It installs an XMRig-based miner, persists via cron, hijacks manaRequest.cgi, and tampers with the web management interface output to hide CPU usage, temperature, and the mining process from users.
QNAP-targeting cryptominer with installer, starter script, malicious CGI, and XMRig miner components. It persists via crontab and tampers with QNAP admin interface metrics to hide high CPU usage and temperature.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.