An attacker breached a Windows honeypot over RDP from two source IPs and installed a Monero cryptominer built around XMRig, disguising payloads as SQL-related files such as sqlserver.exe, sqlsupdater.exe, and sqlsupdater.sfx.exe. The intrusion established persistence through scheduled tasks, Windows services created with NSSM, and a Neshta-style registry hijack of the exefile open command, while built-in tools such as icacls and attrib were used to hide files and restrict access to directories to complicate detection and cleanup. The actor also redirected known mining-pool domains to localhost to suppress competing miners, and the observed wallet had received roughly 1.32 XMR at the time of reporting.
The activity aligns with Windows behaviors commonly tracked by endpoint detections for excessive service-stop attempts and repeated use of net.exe, net1.exe, or sc.exe, which can indicate efforts to disable services, evade security controls, or manipulate accounts during miner deployment. Splunk has since replaced older analytics covering those patterns with updated Windows-focused detections, underscoring that bursts of service tampering and abnormal net utility usage remain relevant signals for identifying cryptomining intrusions and related post-compromise actions on Windows hosts.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Splunk removed the deprecated 'Excessive Usage Of Net App' detection from its Threat Research content library, stating it was renamed and updated. The replacement analytic was listed as 'Windows Excessive Usage Of Net App.'
Splunk removed the deprecated 'Excessive Service Stop Attempt' detection from its Threat Research content library in version 5.2.0, stating it had been renamed and its logic updated. Splunk identified the replacement as 'Windows Excessive Service Stop Attempt.'
The DFIR Report disclosed technical details of the intrusion, including payload names, persistence mechanisms, mining pool domains, file hashes, and the observation that the wallet had received about 1.32 XMR. The report characterized the activity as a Monero cryptomining operation using XMRig.
A threat actor accessed a Windows honeypot over RDP from two source IP addresses and installed an XMRig-based Monero cryptominer masquerading as SQL-related components. The intrusion also established persistence through scheduled tasks, an NSSM-managed service, and a Neshta-style registry hijack.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
research.splunk.com
Open sourceresearch.splunk.com
Open sourcethedfirreport.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.