Cryptocurrency-mining malware continued to expand across enterprise and consumer environments through multiple delivery channels, including social media, malicious advertising, and compromised IoT devices. Trend Micro reported that Digmine spread through Facebook Messenger by posing as a video file, then abusing active Chrome-based Facebook sessions to message additional victims and install a modified XMRig Monero miner. Separately, a malvertising campaign abused Google DoubleClick to serve hidden Coinhive and private web miners on legitimate high-traffic sites, driving a sharp rise in detections while consuming as much as 80% of affected systems’ CPU resources.
Researchers also observed an updated Bashlite variant targeting IoT devices, particularly systems exposing the WeMo UPnP API, adding cryptocurrency-mining, backdoor, DDoS, and device-bricking functions to its botnet activity. The broader threat reflects a long-running pattern in which attackers exploit known vulnerabilities, weak configurations, and trusted platforms to hijack computing resources across desktops, servers, Linux hosts, mobile devices, and IoT systems for illicit mining, while also creating opportunities for persistence, further compromise, and operational disruption.

Pull IOCs and campaign context straight into your stack.
16 events from the most recent confirmed update back to the earliest known activity.
On January 24, 2018, Trend Micro observed a malvertising campaign abusing Google DoubleClick that caused an almost 285% increase in Coinhive web miner detections. The ads ran on legitimate high-traffic websites and covertly consumed about 80% of victims’ CPU resources using Coinhive or a private miner.
Trend Micro began seeing increased traffic to five malicious domains on January 18, 2018, and analysis showed the traffic originated from advertisements distributed through Google DoubleClick.
From January 1 to June 24, 2017, Trend Micro sensors detected 4,894 bitcoin miners that triggered more than 460,259 bitcoin-mining activities, with over 20% also associated with web- and network-based attacks.
A Mirai variant that included bitcoin-mining capabilities appeared in April 2017, showing mining functionality being added to IoT malware.
One of the U.S. Federal Reserve’s servers was misused to mine bitcoins in early February 2017.
Belkin said the WeMo vulnerability targeted by the later Bashlite activity had been detected and remediated for affected devices in 2015.
Bashlite became widely known in 2014 for large-scale distributed-denial-of-service attacks before later variants added mining and other capabilities.
Kagecoin appeared in 2014 as an Android cryptocurrency-mining threat capable of mining bitcoin, litecoin, and dogecoin.
The U.S. National Science Foundation experienced a similar supercomputer cryptocurrency-mining misuse incident in 2014.
Harvard’s Odyssey supercomputer cluster was illicitly used to mine dogecoins in 2014, illustrating misuse of institutional computing resources for cryptocurrency mining.
In January 2014, a vulnerability in Yahoo!'s Java-based advertising network was abused to expose European users to malvertisements that delivered bitcoin-mining malware.
The reference states that hacking tools and backdoors related to illicit bitcoin mining had existed since at least 2011, marking an early stage in cryptocurrency-mining abuse.
Trend Micro reported its findings about the abuse of Google DoubleClick for cryptocurrency-mining malvertising to Google.
After being notified of the findings, Facebook removed many Digmine-related links from its platform to disrupt the malware's Messenger-based propagation.
Researchers first observed the Digmine cryptocurrency-mining bot in South Korea before it spread to other countries. The malware propagated through Facebook Messenger by masquerading as a video file and ultimately deployed a modified XMRig-based Monero miner.
Trend Micro observed the updated Bashlite variant in the wild on March 21, with detections in Taiwan, the United States, Thailand, Malaysia, Japan, and Canada. The variant abused a Metasploit RCE module against devices exposing the WeMo UPnP API and added mining, backdoor, bricking, and expanded DDoS commands.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 42 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
trendaisecurity.com
Open sourcetrendaisecurity.com
Open sourcetrendaisecurity.com
Open sourcetrendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.