Cisco Talos reported a previously unreported Linux botnet dubbed Xanthe that targets internet-exposed systems for Monero mining, including hosts reachable through SSH and exposed Docker APIs on TCP port 2375. The malware is modular and deploys XMRig, spreading primarily by harvesting client-side SSH keys and known-host data, while also abusing misconfigured Docker environments to gain execution on containerized infrastructure.
Once installed, Xanthe uses multiple defense-evasion and persistence techniques to retain control and maximize mining time. Talos said the malware deploys a libprocesshider shared object to conceal miner activity, disables security tools, removes competing miners, weakens SSH settings, creates privileged users, installs attacker SSH keys, modifies firewall rules, and persists through cron jobs and rc.local changes—behavior consistent with the Impair Defenses technique tracked in MITRE ATT&CK as T1562.001.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Cisco Talos assessed that the previously undocumented Xanthe Linux cryptomining botnet had been active since March 2020. The campaign targeted Linux systems, spread via SSH, and also included functionality to exploit exposed Docker APIs.
Cisco Talos reported a cryptocurrency-mining botnet after observing it target one of Cisco’s Docker-related security honeypots and named the malware family Xanthe. Talos described it as a modular Monero-mining campaign using XMRig, persistence mechanisms, process hiding, and defense evasion features.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.