Linux-focused cryptocurrency-mining malware has increasingly targeted servers, cloud workloads, and Docker environments, with attackers abusing the platforms’ reliability, prevalence, and processing power to mine privacy-centric coins such as Monero. The activity reflects a broader shift in cryptojacking operations toward Linux systems and exposed applications or APIs that can be leveraged to gain unauthorized access and sustain mining activity.
Researchers reported that newer Linux cryptominers are not only designed to consume victim resources but also to detect, disable, and remove rival miners already present on compromised machines, effectively turning infected hosts into contested infrastructure. The behavior mirrors tactics seen in earlier malware families including KORKERDS and Skidmap, underscoring how cryptojacking campaigns have evolved from simple resource theft into more persistent and competitive operations aimed at monopolizing compromised compute capacity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.