XMRig is an open-source cryptocurrency mining program most commonly used to mine Monero and other RandomX or CryptoNight-family coins. Although legitimate in benign administrative contexts, it is widely repurposed by threat actors for unauthorized cryptomining on compromised systems. In intrusion reporting, XMRig commonly appears as a final-stage monetization payload delivered after initial compromise through exposed services, brute-force access, software exploitation, malicious loaders, trojanized software, malvertising, or supply-chain style repository abuse.
On Windows, XMRig has been deployed by financially motivated campaigns alongside stealers such as Vidar, by botnet operators such as Phorpiex, and by intruders who establish persistence through services, scheduled tasks, or Run-key mechanisms before launching the miner. It is also observed hidden inside or alongside other malware components, including cases where operators disguise miner files, sideload supporting components, or inject miner-related code into legitimate processes to evade detection. On Linux, XMRig is frequently installed after successful SSH compromise or exploitation of internet-facing applications, then paired with shell-script droppers, cron-based persistence, process-name masquerading, and removal of competing miners or security controls. Cloud and virtualized workloads have also been abused for XMRig-based resource hijacking, including compromised EC2 instances.
Threat actors often deliver XMRig as a separate downloaded component rather than embedding mining logic directly in the initial malware. Observed delivery chains include downloader malware, malicious PowerShell stages, password-protected archives from fake cracked-software sites, trojanized developer tooling, malicious Go modules, and post-exploitation deployment following exploitation of products such as TeamCity or Langflow. Some malware families, including Siggen, can deploy XMRig as one of several monetization payloads. XMRig is also incorporated into custom miner variants and related cryptomining malware, including bespoke builds and malware that reuses XMRig code while adding persistence, propagation, firewall modification, or anti-competition logic.
Its core malicious use case is unauthorized CPU-intensive mining, but operationally it is often part of broader post-compromise activity that includes defense evasion, persistence, and payload staging by the surrounding intrusion set. Victims span consumers, SMBs, enterprise servers, developer workstations, Linux SSH servers, CI/CD infrastructure, and cloud-hosted systems. Because XMRig is a legitimate tool with extensive criminal abuse, attribution generally depends on the surrounding intrusion chain rather than the miner alone.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
26 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
APT29 (Cozy Bear) exploited CVE-2024-27198 in real-world campaigns.
In this case, the attacker was automatically trying to exploit CVE-2024-4577, which affects certain versions of PHP 8 when using Apache and PHP-CGI on Windows.
Threat actors are continuing to exploit a critical Langflow vulnerability as part of fresh attacks designed to deliver a Monero cryptocurrency miner. The activity has been found to weaponize CVE-2026-33017 (CVSS score: 9.3), an unauthenticated remote code execution (RCE) vulnerability in Langflow, indicating threat actors are scanning and targeting exposed artificial intelligence (AI) application endpoints for obtaining initial access to enterprise networks.
The React2Shell vulnerability (CVE-2025–55182) was reported to the React team on November 29. Public advisories and patches dropped on December 3. Threat actors started exploiting it within hours... React2Shell (CVE-2025–55182) is a critical, unauthenticated remote code execution bug in React Server Components’ “Flight” protocol. | Common post-exploitation moves: Install XMRig or another cryptominer
Along with patching, we recommend examining SAP web server access logs for additional evidence of CVE-2025-31324 exploitation, specifically looking for evidence of unusual requests to the API endpoint /developmentserver/metadatauploader . If possible, consider disallowing access to that API endpoint from external networks. To hunt for additional evidence of web shell uploads, organizations can search for unexpected JSP files within these folders on SAP servers... | hxxp[://]23.95.123[.]5:666/xmrigCCall/8bq.sh
This service is accompanied by a pipe named \\.\WinRing0_1_2_0 which allows the process to communicate with the driver. This is quite an old driver, vulnerable to CVE-2020-14979 and CVE-2021-41285, and allowing the actor to elevate privileges to NT\SYSTEM as soon as the direct unchecked communication with the driver is allowed and the attacker controls input forwarded to the driver.
This service is accompanied by a pipe named \\.\WinRing0_1_2_0 which allows the process to communicate with the driver. This is quite an old driver, vulnerable to CVE-2020-14979 and CVE-2021-41285, and allowing the actor to elevate privileges to NT\SYSTEM as soon as the direct unchecked communication with the driver is allowed and the attacker controls input forwarded to the driver.
Ahnlab Security Emergency response Center (ASEC) has recently confirmed that the 8220 Gang attack group is using the Log4Shell vulnerability to install CoinMiner in VMware Horizon servers. Log4Shell (CVE-2021-44228) is both a remote code execution vulnerability and the Java-based logging utility Log4j vulnerability... | If the CVE-2022-26134 vulnerability attack succeeds, the following PowerShell command downloads and executes additional PowerShell scripts and ultimately installs XMRig CoinMiner.
The group targets not only global systems but also Korean ones. ASEC has introduced a case where the attack group abused the Atlassian Confluence server vulnerability CVE-2022-26134 to attack Korean systems and install CoinMiner. | If the CVE-2022-26134 vulnerability attack succeeds, the following PowerShell command downloads and executes additional PowerShell scripts and ultimately installs XMRig CoinMiner.
In this cluster of activity, since at least March 25, 2026, an XMRig sample and its accompanying configuration file were downloaded and deployed via a shell script.
In this cluster of activity, since at least March 25, 2026, an XMRig sample and its accompanying configuration file were downloaded and deployed via a shell script.
In this cluster of activity, since at least March 25, 2026, an XMRig sample and its accompanying configuration file were downloaded and deployed via a shell script.
Several devices initiated TCP connections to endpoints affiliated with cryptomining pools such as us[.]zephyr[.]herominers[.]com and xmrig[.]com. Connectivity to these domains indicates likely successful installation of mining software during earlier stages of post-compromise activity.
Several devices initiated TCP connections to endpoints affiliated with cryptomining pools such as us[.]zephyr[.]herominers[.]com and xmrig[.]com. Connectivity to these domains indicates likely successful installation of mining software during earlier stages of post-compromise activity.
CVE-2022-22954, a remote code execution (RCE) vulnerability due to server-side template injection in VMware Workspace ONE Access and Identity Manager, is trivial to exploit with a single HTTP request to a vulnerable device.
Apache RocketMQ Exploit Module (CVE-2023-33246) ... In June 2023, a vulnerability cataloged as CVE-2023-33246 was discovered that enables an attacker to achieve remote command execution (RCE) on RocketMQ versions 5.1.0 and earlier. Shortly after, DreamBus added an exploit module to target this vulnerability.
Metabase Exploit Module (CVE-2023-38646) ... The open source versions of Metabase 0.46.6.1 and earlier, as well as Metabase Enterprise 1.46.6.1 and earlier, are vulnerable to CVE-2023-38646 ... The vulnerability allows an attacker to execute arbitrary commands on the server. The DreamBus exploit targeting the vulnerability is likely based on an open source proof-of-concept.
The attack, at its core, exploits a critical missing authentication bug (CVE-2023-48022, CVSS score: 9.8) to take control of susceptible instances and hijack their computing power for illicit cryptocurrency mining using XMRig.
CVE-2026-20182 carries a CVSSv3.1 score of 10.0 (Critical) and is classified under CWE-287: Improper Authentication. The flaw affects the Cisco Catalyst SD-WAN Controller (formerly vSmart)... The peering authentication mechanism is not functioning correctly, allowing an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on the affected system.
Apr 2024 PAN-OS CVE-2024-3400 exploit integration (Akamai)
Analysis of react.py This script is clearly set to exploit CVE-2025-29927, also known as React2Shell. ... This script implements a fully automated React/Next.js exploitation pipeline centered on abusing CVE-2025-29927 to achieve remote command execution at scale.
Malware campaigns include the Muhstik botnet and XMRig Monero Cryptocurrency mining. | Drupal versions before 7.58... allow remote attackers to execute arbitrary code... Malware campaigns include the Muhstik botnet and XMRig Monero Cryptocurrency mining.
The PoC repository contained a PDF file... downloading and running three files: Xsession.sh → The main malware script; xsession.auth → A disguised Monero miner (XMRig); xprintidle → A utility to detect when the system was idle. | Late at night, I was testing a proof-of-concept (PoC) exploit for CVE-2020-35489 ... The script appears to be a simple Proof-of-Concept (PoC) for an exploit, but in reality, it contains hidden malicious functionality.
“CoinMiner XMRig, a CoinMiner that mines the Monero cryptocurrency, was the one the most used in the attacks.”
"x522, which kills competing miners such as XMRig and Kinsing, and launches the miner with a c3pool.org configuration"
The Kaswara Modern WPBakery Page Builder plugin (CVE-2021-24284) is an example of this. This is a five-year-old unpatched flaw in a long-abandoned plugin that attackers are still actively exploiting right now... This flaw allows an unauthenticated attacker to upload malicious code directly to a vulnerable server and execute it remotely. | "...attackers have been using this vulnerability to take over WordPress websites... to ultimately install unauthorized copies of the XMRig cryptomining software"
23 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The observed tactics, targeting, and tradecraft closely align with the Rare Werewolf (Librarian Ghouls) threat actor, although no XMRig cryptomining activity was observed in this sample.
The observed tactics, targeting, and tradecraft closely align with the Rare Werewolf (Librarian Ghouls) threat actor, although no XMRig cryptomining activity was observed in this sample.
Blue Mockingbird has made their XMRIG payloads persistent as a Windows Service.
By querying the hash on threat intelligence portals and by statically analyzing the sample, it became clear that this binary is a malicious modified version of XMRig (6.19.0), a cryptocurrency miner.
One of the campaigns deployed an XMRig cryptocurrency miner on a small number of infected machines, which is not standard behavior for a disciplined intelligence operation.
Impact T1496 Resource Hijacking TeamPCP kills competing XMRig cryptominers before deploying own payloads
27 distinct techniques documented for this family, organized by ATT&CK tactic.
Threat actors are targeting consumers and small to midsize businesses (SMBs) globally in a financially motivated malvertising campaign... An attack begins when someone clicks on a malicious online ad for pirated or cracked software, which redirects them to attacker-controlled websites hosting the password-protected archives
the activity appears to follow a sequence often seen in compromises of internet-facing systems: brute-forced access, payload delivery, and repeated outbound connectivity to mining pool infrastructure.
Finally, the loader establishes persistence through Windows Registry Run keys and scheduled tasks to ensure the malware survives system reboots.
the EC2 instance downloaded 3.42 MB of data over an HTTP connection on port 80 to the external endpoint, 185.62.1[.]8, which appears to host a ZIP file containing XMRig crypto-mining malware.
At last, sysmgnrsv.exe is run through CMD. This indirect execution through cmd.exe is an evasion technique that can help bypass some security tools and process monitoring that might have rules against directly executing suspicious executables.
Finally, the loader establishes persistence through Windows Registry Run keys and scheduled tasks to ensure the malware survives system reboots.
the activity appears to follow a sequence often seen in compromises of internet-facing systems: brute-forced access, payload delivery, and repeated outbound connectivity to mining pool infrastructure.
Stage 1: Internet-exposed SSH enabled initial access ... the LiteLLM-Proxy EC2 instance appeared to be externally exposed over SSH, with port 22 open to 0.0.0.0/0.
Finally, the loader establishes persistence through Windows Registry Run keys and scheduled tasks to ensure the malware survives system reboots.
the activity appears to follow a sequence often seen in compromises of internet-facing systems: brute-forced access, payload delivery, and repeated outbound connectivity to mining pool infrastructure.
The loader also is signed with a fabricated certificate for JustWatch... and uses an unusually large file size via padding with null bytes to evade detection by automated analysis.
Those two files with modified characteristics ( edge.exe and Taskgmr.ps1 ) were sitting in C:\Program Files (x86)\Microsoft\EdgeUpdate\ .
Darktrace observed the LiteLLM-Proxy EC2 instance connecting to the hostname pool.hasvault[.]pro over HTTPs on port 443. Following the initial connection, repeated outbound connectivity to the same hostname was observed.
During dynamic analysis, it was observed that the sample invokes the URLDownloadToFileW API from urlmon.dll to retrieve a remote payload from a remote server... This behavior demonstrates that the analyzed sample functions as a downloader, where the initial executable retrieves a secondary-stage payload from an external server and stores it within the user’s temporary directory for subsequent execution.
504 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
XMRig is deployed here as a malicious Monero miner payload. The malware downloads and executes it with attacker-controlled pool and wallet parameters, turning the victim host into a cryptocurrency mining bot while limiting CPU usage to reduce suspicion.
Mining software used as the basis for a separate cryptocurrency-mining component deployed by the Siggen backdoor on compromised devices.
Cryptocurrency mining malware/tool deployed on the compromised endpoint, with persistence created via nssm.exe and files hidden using modified attributes.
Monero cryptominer-related payload observed among malware files in the campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.