Kaspersky reported that the open-source XMRig Monero miner was being folded into broader malware operations, including a "ransominer" chain that monetized victims before any ransom was paid. In one observed intrusion, attackers used a generic Trojan to install administrative tools, create a new user account, enable RDP access, deploy Trojan-Ransom.Win32.Crusis, and then launch an XMRig loader so the compromised host immediately began generating cryptocurrency for the attackers.
Telemetry showed more than 5,000 attempts in August 2020 to install XMRig or modified variants, with Prometei and Cliptomaner identified as major distributors. Prometei brute-forced MS SQL credentials, abused xp_cmdshell and CVE-2016-0099, and used a cross-platform .NET Core/Apphost loader to fetch miner payloads for Windows and Linux systems. Cliptomaner, first detected in September 2020, posed as Realtek audio software, was written in AutoIT, mined cryptocurrency, and also hijacked copied wallet addresses by replacing them with attacker-controlled ones.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
In October 2020, Kaspersky research examined how the open-source XMRig Monero miner was being bundled into broader malware campaigns, including ransominer activity and distribution by Prometei and Cliptomaner.
In September 2020, Kaspersky detected a newly identified malware family called Cliptomaner. It masqueraded as Realtek audio software, was written in AutoIT, mined cryptocurrency, and replaced copied wallet addresses with attacker-controlled ones.
Kaspersky Security Network telemetry showed more than 5,000 attempts during August 2020 to install XMRig or modified variants. The activity was linked in part to distribution by Prometei and other malware operators.
In an observed case in August 2020, attackers used a generic Trojan to install admin tools, create a new user, enable RDP, launch Trojan-Ransom.Win32.Crusis, and then start an XMRig loader to mine cryptocurrency before any ransom was paid.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.