XMRig is legitimate, open-source cryptocurrency-mining software widely abused for cryptojacking, particularly unauthorized Monero mining. Malicious deployments consume compromised systems’ processing resources and direct mining proceeds to attacker-controlled wallets through cryptocurrency mining pools. XMRig is a mining payload rather than inherently a credential stealer, ransomware family, or self-propagating bot; those functions belong to other components in campaigns that deploy it.
Unauthorized deployments affect Windows and Linux systems, enterprise servers, cloud workloads, Docker containers, and compromised network gateways. Attackers install XMRig after exploiting internet-facing applications, including VMware Horizon through Log4Shell, Windows PHP through CVE-2024-4577, JetBrains TeamCity, Adobe ColdFusion, Jenkins, and AhsayCBS. Distribution also includes ClickFix social engineering: malicious Steam forum replies offer fake troubleshooting instructions that persuade users to execute elevated PowerShell commands. Repository compromise has additionally been used to embed XMRig in a project's Docker image.
Campaigns commonly surround the miner with persistence and concealment mechanisms. These include Windows services and scheduled tasks, Linux cron jobs, and watchdog routines that restart mining after termination or reboot. Attackers disguise mining executables and services as Microsoft Edge components, Windows maintenance utilities, or other legitimate processes. Supporting scripts can add Microsoft Defender exclusions and suspend mining while Task Manager is open. Container-based deployments have also used packed binaries, encrypted configuration, and hidden execution locations.
XMRig has been deployed in TeamTNT and H2Miner operations, by the Sysrv-hello cryptomining botnet, and alongside Lcrypt0rx ransomware. Its use spans unrelated operators and campaigns, so the miner alone does not establish threat-actor attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
29 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
During routine sandbox hunting analysis, the Uptycs Threat Research team uncovered evidence of an ongoing live campaign exploiting the Log4j vulnerability, which commenced in January 2024.
2024년 5월 HFS의 원격 코드 실행 취약점인 CVE-2024-23692가 공개되었으며 이를 활용할 경우 공격자는 HFS에 명령이 포함된 패킷을 전송하여 HFS가 악성 명령을 실행하도록 할 수 있다.
GeoServer의 원격 코드 실행 취약점(CVE-2024-36401)이 공개된 이후 최근까지도 해당 취약점을 악용해 악성코드를 설치하는 사례들이 확인되고 있다.
“The major attack cases are CVE-2021-26084 and CVE-2022-26134. They are remote code execution vulnerabilities...” The article also states that “z0miner is a CoinMiner distributed using various vulnerabilities such as CVE-2021-26084.”
최근 국내 취약한 ActiveMQ 서버를 대상으로 CVE-2023-46604 취약점 공격을 통해 악성코드를 유포하는 사례가 확인되었다.
AWS reported within hours of public disclosure, multiple China state-nexus threat groups, including Earth Lamia and Jackpot Panda, had been exploiting CVE-2025-55182 for initial access.
On June 2, Atlassian published an advisory for CVE-2022-26134, a critical zero-day remote code execution vulnerability in Confluence Server and Data Center.
Malicious activity exploiting the recently disclosed Oracle WebLogic critical deserialization vulnerability (CVE-2019-2725) is surging. Payloads include Sodinokibi, Muhstik, XMRig, and GandCrab.
The Ruby on Rails base64 encoded attack vector exploits CVE-2013-0156. [...] Once the vulnerability has been exploited the code can start running.
CVE-2026-105134 ... can be leveraged for OS command injection. ... After gaining access, Huntress observed the attacker perform reconnaissance, deploy Java Server Page (JSP) webshells, and download the XMRig miner disguised as edge.exe. | After gaining access, Huntress observed the attacker perform reconnaissance, deploy Java Server Page (JSP) webshells, and download the XMRig miner disguised as edge.exe.
The threat actor chained the two vulnerabilities, CVE-2026-105133 first to bypass authentication and then CVE-2026-105134 for code execution. | After gaining access, Huntress observed the attacker perform reconnaissance, deploy Java Server Page (JSP) webshells, and download the XMRig miner disguised as edge.exe.
This vulnerability allows an authenticated administrator to send specially crafted requests and to execute arbitrary commands on the appliance. | Location: hxxp://45.130.22[.]219/ivanti Description: ELF file for XMRIG Monero Cryptominer
The Confluence widget connector vulnerability CVE-2019-3396 was exploited to deliver GandCrab ransomware and cryptocurrency-mining malware containing a rootkit.
F5 researchers recently discovered a new campaign targeting Jenkins automation servers that exploits an unauthenticated code execution vulnerability (CVE-2017-1000353). | The first noticeable text includes XMRig options, which implies XMRig is embedded into this malware.
The original vulnerabilities CVE-2023-46805 and CVE-2024-21887 have been actively exploited by a range of threat actors with varying levels of sophistication ... since at least early December 2023. | Location: hxxp://45.130.22[.]219/ivanti Description: ELF file for XMRIG Monero Cryptominer
The TellYouThePass ransomware gang has been leveraging CVE-2024-4577, a remote code execution vulnerability in PHP to deliver web shells and deploy ransomware on targeted systems. | July 11, 2024: Multiple malware campaigns targets the PHP vulnerability: Gh0st RAT, RedTail crypto miners, and XMRig.
The vulnerability, with a CVSS 3.1 score of 9.8, affects the Netgear DGN1000, firmware < 1.1.00.48 and Netgear DGN2000 v1 routers. Netgear no longer supports these routers, and the vulnerability is pretty serious since it allows authentication bypass and command injection.
The report lists Adobe.ColdFusion.CVE-2023-29300.Insecure.Deserialization among signatures for the vulnerabilities discussed and states that attacks continue despite previously released security updates.
CVE-2024-27198 is a critical authentication bypass vulnerability identified within the web component of JetBrains TeamCity versions before 2023.11.4. This vulnerability enables remote unauthenticated attackers to circumvent authentication checks by crafting specific URLs. | Actors associated with the BianLian and Jasmin ransomware families have weaponized the vulnerability to distribute payloads such as the XMRig cryptocurrency miner and Spark RAT.
The report lists Adobe.ColdFusion.CVE-2023-38203.Insecure.Deserialization among signatures for the vulnerabilities discussed. Attackers inject payloads into the argumentCollection parameter through POST requests to /CFIDE/adminapi/accessmanager.cfc.
The report lists Adobe.ColdFusion.CVE-2023-38204.Insecure.Deserialization among signatures for the vulnerabilities discussed and describes ongoing probing, reverse-shell activity, and malware deployment against Adobe ColdFusion.
The people behind it use high severity, public vulnerabilities to continue installing their RAT and miner, such as the recent Apache Path Traversal CVE-2021-41773.
The threat actor used WebLogic vulnerabilities such as CVE-2020-14882 to upload JSP WebShell.
Ray Jobs API ( /api/jobs/ ) принимает произвольный код на Python без аутентификации. ... Параллельно с RondoDox действует группировка IronErn440 с кампанией ShadowRay 2.0, нацеленной на CVE-2023-48022.
Атакующий комбинирует подмену User-Agent с DNS rebinding ... Исправлена в Ray 2.52.0. ... RondoDox добавил CVE-2025-62593 ... за два дня до публичного раскрытия PoC.
CVE-2023-22527 is a critical CVSS 10 template-injection vulnerability in older Confluence Data Center and Confluence Server versions that permits unauthenticated remote code execution. The content reports active exploitation for cryptojacking, including deployment of XMRig miners, SSH-based propagation, cron persistence, security-tool removal, and log/history clearing. | Threat actors exploiting CVE-2023-22527 deployed the XMRig miner, including via an ELF payload and a shell script that downloads XMRig after disabling security tooling and establishing cron-based persistence.
The hash c63f646edfddb4232afa5618e3fac4eee1b4b115 was identified as an XMRig Miner among hashes observed in attacks exploiting CVE-2024-0012.
CVE-2026-65400 (CVSS 9.8, CWE-287: Improper Authentication) — pre-auth уязвимость... Пароль не нужен... Apple закрыла в macOS Tahoe 26.6.1, Sequoia 15.7.9, Sonoma 14.8.9. CISA: SSVC «Act» — active exploitation, automatable, total technical impact.
CVE-2026-42271, command injection in test endpoints. For the second flaw, attackers submitted a fake MCP server configuration whose command field launched a Python downloader and cryptominer.
52 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Resource hijacking and deploying XMRig Docker images to mine cryptocurrency.
Notably, this XMRig miner is also deployed by the Lcrypt0rx ransomware variant.
The use of variants of the open-source miner XMRig intended for botnet mining, with versions dependent on the victim's architecture.
XMRig의 설정 파일에는 과거 Fortinet 보고서에서 언급된 Kinsing 공격자의 지갑 주소가 포함되어 있다.
If the vulnerability attack succeeds, the group ultimately installs Monero CoinMiner (XMRig).
가장 많이 사용된 악성코드는 모네로 가상 화폐를 채굴하는 XMRig이며 적어도 4개의 공격자들이 HFS를 공격하여 코인 마이너를 설치하고 있다.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
It deletes all cron jobs, and adds a new one that runs every five minutes to check for command-and-control (C&C) server connectivity.
Création d’une tâche planifiée nommée XMRig-[nom_machine] lançant system.exe avec les privilèges SYSTEM à chaque démarrage Windows.
Le script PowerShell se fait passer pour un utilitaire d’optimisation Windows nommé “msf utility \ PC Opt”.
The attacker downloaded the shell file and ran it with bash from memory.
It deletes all cron jobs, and adds a new one that runs every five minutes to check for command-and-control (C&C) server connectivity.
It deletes all cron jobs, and adds a new one that runs every five minutes to check for command-and-control (C&C) server connectivity.
The threat actor is using 2 Processhider rootkits to hide the cryptominer (tmp) and all SH commands.
Ces fonctions sont factices et n’effectuent aucune action réelle, affichant uniquement de faux messages de progression avec des pauses aléatoires.
Named the service MicrosoftEdgeUpdateSvc to look like the legitimate Edge Update service (edgeupdate).
Renamed the NSSM utility to msedge.exe and the XMR miner to edge.exe.
The attacker removes all their traces by clearing log and bash history.
T1071.001 — Application Layer Protocol: Web Protocols (Command and Control)
Téléchargement du payload XMRig depuis https://msfconfig[.]icu:443/tmp/system.txt vers un fichier temporaire aléatoire
1,481 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cryptocurrency-mining software abused in the reported campaign by embedding it in the DevOpsGPT project's Docker image. The article does not describe its execution or mining configuration.
Deployed for unauthorized cryptocurrency mining after attackers chained authentication bypass and OS command injection vulnerabilities in AhsayCBS. The miner was disguised as edge.exe and persisted through the MicrosoftEdgeUpdateSvc service using a modified NSSM utility. A PowerShell script concealed mining by stopping the service while Task Manager was open and restarting it afterward. In one incident, a vulnerable WinRing0x64.sys driver was also deployed, likely to increase hardware access for mining.
Cryptocurrency-mining software deployed maliciously after attackers chain authentication-bypass and remote-code-execution vulnerabilities in AhsayCBS. The mining operation masquerades as Microsoft Edge and uses a SYSTEM-level service, modified service-management tooling, and a legitimate kernel driver. An accompanying PowerShell script terminates itself when Task Manager remains open for more than 50 seconds and monitors subsequent reopening, indicating detection-evasion behavior.
Threat actors deployed XMRig on compromised AhsayCBS backup servers after exploiting an authentication-bypass and command-injection chain. The miners masqueraded as Microsoft Edge using the filename edge.exe. An accompanying PowerShell script, Taskgmr.ps1, supported mining operations by stopping mining when Windows Task Manager opened and terminating Task Manager under specified conditions. In one incident, attackers also downloaded the legitimate-but-vulnerable WinRing0x64.sys driver, reportedly to obtain hardware access and optimize mining.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.