Researchers reported that large-scale botnets continued to spread by abusing known, wormable vulnerabilities and weakly defended internet-facing systems. Proofpoint detailed the Smominru operation, a Monero cryptomining botnet that infected more than 526,000 Windows hosts—likely many of them servers—primarily through the EternalBlue SMB flaw (CVE-2017-0144), with indications of additional use of EsteemAudit (CVE-2017-0176) and attacks via SQL Server. The operators were estimated to have mined about 8,900 Monero, worth roughly $2.8 million to $3.6 million at the time, while using Windows Management Instrumentation in an unusual way to support propagation and mining.
Separate research highlighted a Mirai spreader that introduced additional risk by expanding the malware’s ability to compromise vulnerable devices and propagate further across exposed environments. Together, the reports show threat actors repeatedly monetizing unpatched infrastructure through self-spreading malware, while adapting quickly when defenders disrupt infrastructure, block wallets, or sinkhole command-and-control resources. The activity underscored the operational and financial impact on organizations, including degraded server performance, increased energy costs, and continued exposure from legacy vulnerabilities that remained widely exploitable.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Proofpoint reported that it had monitored the Smominru Monero-mining botnet since the end of May 2017. The botnet spread primarily via the EternalBlue SMB exploit and was also assessed to likely use other propagation methods.
After MineXMR took action, the botnet operators registered new domains and switched mining to a new Monero address on the same pool. Proofpoint said the operators appeared to lose control of about one third of the botnet during the transition before recovering to about two thirds of the prior hash rate.
Proofpoint contacted the MineXMR mining pool and requested that the Monero address associated with Smominru be banned. MineXMR acted several days after the operation began, disrupting the botnet's mining activity.
During a sinkholing operation conducted with abuse.ch and the ShadowServer Foundation, Proofpoint found that Smominru included more than 526,000 infected Windows hosts worldwide. The highest observed concentrations were in Russia, India, and Taiwan, and most infected nodes were believed to be Windows servers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.