A surge in coordinated cryptojacking attacks has targeted PHP and PHP-based frameworks, with threat actors exploiting multiple remote code execution (RCE) vulnerabilities such as those in ThinkPHP, PHP CGI, and PHPUnit. Telemetry from August through November 2025 shows a significant increase in exploitation attempts, with attackers leveraging both recent and older vulnerabilities—including CVE-2024-4577 and CVE-2019-9082—to deploy cryptominers at scale. The campaigns are characterized by shared infrastructure and tooling, indicating a high degree of coordination, and are primarily driven by the profitability of cryptocurrency mining amid rising Bitcoin prices.
Attackers are utilizing a mix of compromised virtual machines, misconfigured services, and rented cloud infrastructure from major providers like Cloudflare, DigitalOcean, Google, and Contabo. The activity is global, with significant participation from German, Taiwanese, Chinese, and North American hosting platforms. The economic incentive is heightened by the recent surge in cryptocurrency values, making large-scale cryptomining operations increasingly attractive to cybercriminals. Organizations running PHP-based applications are at heightened risk and should prioritize patching known RCE vulnerabilities to mitigate exposure to these ongoing campaigns.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
A follow-up report described the activity as a coordinated cryptojacking blitz abusing ThinkPHP and PHP RCE flaws to maximize mining revenue, reinforcing the scope and intent of the campaign.
GreyNoise publicly reported on the ongoing PHP cryptomining activity, describing the campaign as active during October and November 2025 and highlighting exploitation observed in the wild.
In October 2025, attackers began a coordinated cryptomining campaign exploiting remote code execution vulnerabilities in PHP applications, including ThinkPHP, to deploy mining payloads on exposed servers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.