H2Miner, also stylized h2Miner, is a financially motivated cryptocurrency-mining operation active since late 2019. It compromises Internet-exposed servers and containerized environments to deploy Kinsing malware and cryptocurrency miners, including XMRig. Its targets include cloud servers in China; its country of origin is not established. H2Miner gains initial access through unauthenticated or weakly protected Redis services, exposed Docker management interfaces, and vulnerable server applications. Its Redis attack chain abuses master–replica replication to transfer a malicious shared library, then loads that library as a Redis module to execute commands and establish reverse shells. Other documented entry points include Apache Solr, Hadoop YARN, ThinkPHP, and Confluence, including exploitation of CVE-2019-0193 and CVE-2019-3396. Its tooling downloads and executes additional payloads, communicates with command-and-control infrastructure, collects host characteristics, and uses masscan to identify additional targets. Deployment scripts terminate competing miners and selected security, database, and application processes, interfere with cloud-security agents, and establish persistence through services and scheduled jobs. Defense-evasion measures include clearing shell history, removing competing scheduled tasks, and reversing Redis configuration changes after exploitation. Associated infrastructure has also distributed Windows mining payloads with scheduled-task persistence. Infrastructure associated with H2Miner has exhibited operational overlap with Lcrypt0rx ransomware through shared mining payloads and a previously associated Monero wallet. This overlap does not establish common ownership or justify attributing Lcrypt0rx's ransomware behavior to H2Miner.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operates a Linux cryptocurrency-mining botnet that compromises exposed services, executes malicious scripts and binaries, maintains command-and-control communications, and scans for additional vulnerable hosts. The reported outbreak primarily abuses unauthenticated or weakly protected Redis services and master-slave replication to deploy and load a malicious module.
Financially motivated activity targeting Linux, Windows, and containerized environments to deploy Monero miners. The campaign reuses older scripts and malware with updated infrastructure and configurations, deploys Kinsing, disables defenses, and removes competing miners. Researchers identified operational overlap with Lcrypt0rx ransomware through shared XMRig payloads, infrastructure, and a previously associated Monero wallet. Whether this reflects collaboration, development by H2Miner operators, or reuse of another operator's ransomware remains unresolved. Additional stealers and remote-access payloads appear in the overlapping delivery chain. The cited CVEs concern historical campaigns associated with recovered Kinsing samples; the report does not establish their exploitation in the current campaign. No specific geographic targets, industry targets, or state sponsorship are identified.
Referenced as background comparison for similar cryptomining tradecraft involving cloud servers.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.