A Linux cloud cryptojacking campaign deployed the CHAOS RAT alongside an XMRig Monero miner, expanding a typical resource-theft intrusion into a broader remote-access compromise. The infection chain retained common miner tradecraft, including killing competing malware and resource-intensive processes, establishing persistence through /etc/crontab, and using Pastebin plus multiple hosting locations to fetch payloads. Researchers said the operators also separated payload delivery infrastructure from command-and-control, with the payload server appearing to be in Russia and the RAT C2 likely geolocated in Hong Kong.
The Go-based CHAOS RAT gave attackers capabilities beyond mining, including reverse shell access, file transfer, screenshot capture, system reconnaissance, and host reboot or shutdown. The malware authenticated to its C2 with a hardcoded JSON Web Token supplied at compile time, illustrating a more structured command channel than is typical in basic cryptomining infections. The combination of persistence, miner deployment, and full-featured remote administration showed how Linux cloud-focused threats were evolving from opportunistic cryptojacking into multi-purpose post-compromise operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
In November 2022, Trend Micro researchers intercepted a Linux cloud cryptojacking campaign targeting Linux machines and cloud instances. The infection chain deployed XMRig mining components and added the CHAOS Remote Administrative Tool, expanding attacker control beyond cryptocurrency mining.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.