SilentCryptoMiner is a Windows-focused covert cryptocurrency miner derived from the open-source XMRig miner. It hijacks victim CPU and GPU resources to mine Monero and, depending on build configuration, may support other cryptocurrencies and mining algorithms. Documented variants use direct system calls, process injection or process hollowing, anti-analysis checks, and suspension of mining when security or analysis tools are detected. Some variants use the WinRing0 driver to tune processor settings for improved mining performance.
SilentCryptoMiner establishes persistence through scheduled tasks, services, or user-level autorun mechanisms, and can disable sleep and hibernation to maximize mining uptime. Certain variants inject a watchdog into a Windows process; the watchdog monitors the miner and restores removed payloads and persistence artifacts. A later campaign variant collected hardware identifiers and exfiltrated them through DNS tunneling disguised as benign traffic. That campaign also used DLL side-loading, in-memory reflective loading, and, when elevated, disabled security controls.
SilentCryptoMiner has been distributed through trojanized or fake software installers, fake VPN and network-restriction-bypass tools, fake media-player or browser-update prompts on pirated-content sites, and steganographically embedded components. The financially motivated cluster tracked as REF1695 deployed SilentCryptoMiner alongside remote-access malware and custom XMRig loaders in fake-installer campaigns active since late 2023. Other campaigns particularly targeted Russian Windows users with trojanized restriction-bypass utilities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Umnr_-prefixed loader is a Themida-packed SilentCryptoMiner loader that injects a watchdog into conhost.exe and a miner into explorer.exe.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
Campaign 2 registers a scheduled task named SVCConfig with an ONLOGON trigger and HIGHEST privilege; CNB Bot creates HostDataProcess to run every 10 minutes.
operators retain full authority to run arbitrary commands or custom shellcode remotely
the original start script general.bat had been modified to run this file using PowerShell.
The malicious executable is a simple loader written in Python and packed into an executable application using PyInstaller. In some cases, the script has been additionally obfuscated using the PyArmor library.
SilentCryptoMiner uses direct syscalls instead of NTDLL functions and invokes NtCreateUserProcess, NtCreateSection, NtMapViewOfSection, NtSetContextThread, and NtResumeThread.
a hidden function inside the file actively triggers a strategic stack overflow ... This overflow systematically builds a customized return-oriented programming chain to decrypt the primary payload
the developers recommend disabling security solutions, citing false positives... In one version, if the security solution on the victim’s device deleted the malicious file, the modified start script displayed the message “File not found, disable all antiviruses and re-download the file, that will help!”
Campaign 2 registers a scheduled task named SVCConfig with an ONLOGON trigger and HIGHEST privilege; CNB Bot creates HostDataProcess to run every 10 minutes.
Campaign 2 registers a scheduled task named SVCConfig with an ONLOGON trigger and HIGHEST privilege; CNB Bot creates HostDataProcess to run every 10 minutes.
SilentCryptoMiner injects a watchdog into conhost.exe and a miner into explorer.exe, mapping a payload into a suspended target process and redirecting its entry point.
SilentCryptoMiner creates a new suspended process with a spoofed parent process by passing an explorer.exe handle in a PS_ATTRIBUTE_LIST to NtCreateUserProcess.
The loader creates a service named DrvSvc and sets its description to that of the legitimate Windows Image Acquisition (WIA) service.
In some cases, the script has been additionally obfuscated using the PyArmor library.
The miner configuration is Base64-encoded and encrypted using the AES-CBC algorithm
They started distributing malware under the guise of restriction bypass programs and injecting malicious code into existing programs.
The loader creates a service named DrvSvc and sets its description to that of the legitimate Windows Image Acquisition (WIA) service.
Stage 2 drops a malicious svchost.exe; SilentCryptoMiner copies itself to Appdata/Local/OptimizeMS/optims.exe to masquerade as legitimate software.
SilentCryptoMiner injects a watchdog into conhost.exe and a miner into explorer.exe, mapping a payload into a suspended target process and redirecting its entry point.
SilentCryptoMiner creates a new suspended process with a spoofed parent process by passing an explorer.exe handle in a PS_ATTRIBUTE_LIST to NtCreateUserProcess.
For stealth, SilentCryptoMiner employs process hollowing to inject the miner code into a system process (in this case, dwm.exe).
Scanning the current environment for artifacts of running on a virtual machine or in a sandbox. The loader compares system data... with predefined lists of values used by virtual environments.
the main module gathers basic processor metadata and disk serial numbers
Scanning the current environment for artifacts of running on a virtual machine or in a sandbox. The loader compares system data... with predefined lists of values used by virtual environments.
CNB Bot communicates with C2 by HTTP POST requests; PureRAT uses configured web C2 servers to receive encrypted Protobuf command messages.
It then transmits this hardware information by utilizing advanced DNS tunneling techniques
55 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A customized cryptomining malware variant delivered via fake update/installers on pirated streaming and ebook sites. It uses DLL side-loading, junk code padding, a stack overflow and ROP chain to decrypt and reflectively load its main module in memory, exfiltrates host metadata over DNS tunneling, disables security tools when elevated, persists with a watchdog, and includes remote command execution capability via a RAT component.
A modified open-source cryptocurrency miner used to silently mine cryptocurrency on victim systems using CPU and GPU resources.
Cryptomining malware used to hijack victim hardware for Monero mining while evading detection by stopping mining when security tools are opened and restarting afterward.
A miner that uses direct system calls to evade detection, disables Windows Sleep and Hibernate modes, establishes persistence via a scheduled task, uses the Winring0.sys driver to tune CPU settings for mining, and is protected by a watchdog process that restores deleted artifacts and persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.