Ethminer is an open-source Ethereum cryptocurrency mining program used to perform GPU-accelerated cryptomining on systems with suitable graphics hardware. Although it is legitimate software, it is frequently repurposed by threat actors as a malicious payload in cryptojacking operations. Observed abuse includes deployment in compromised Kubernetes and Kubeflow environments, where attackers launch GPU-capable containers to mine Ethereum, and installation on compromised Windows hosts as part of broader malware chains.
In cloud-native intrusions, Ethminer has been used in campaigns targeting internet-exposed Kubeflow deployments. Attackers abused insecure access to Kubeflow dashboards and pipelines to create malicious workflows that launched TensorFlow GPU containers and executed Ethminer to monetize cluster GPU resources. These operations were accompanied by reconnaissance of available CPU and GPU capacity and were designed to blend into machine-learning environments by using legitimate container images.
Ethminer has also appeared as a secondary payload in Windows crimeware activity associated with ServHelper campaigns linked with moderate confidence to TA505 or a related cluster. In those intrusions, the miner was conditionally deployed after host profiling indicated suitable graphics capability, then staged in encrypted form and reflectively injected into a legitimate process to evade detection. In this role, Ethminer functioned as a monetization component alongside remote-access, credential and cookie theft, and other post-compromise capabilities provided by the primary malware.
When abused maliciously, Ethminer’s role is cryptomining rather than access brokerage or data theft. Its observed malicious use is typically post-compromise and depends on prior unauthorized access established through exposed administrative interfaces or multi-stage malware delivery chains.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
Raccoon ... downloads and installs a ServHelper RAT if instructed by the command and control (C2) server. Attackers also deploy the ServHelper RAT with a variant of the Amadey malware which gets a full command line from the server to install an initial PowerShell downloader component for ServHelper.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Ethereum mining payload optionally downloaded by the ServHelper-associated cryptomining module and loaded into memory on infected hosts.
Miner archive hosted on the server as part of the actor toolkit.
Open-source cryptocurrency miner used in the campaign's GPU-focused container to mine cryptocurrency on compromised Kubeflow/Kubernetes clusters.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.