The Kingminer botnet has been repeatedly observed compromising publicly exposed Microsoft SQL Server instances by brute-forcing weak credentials on TCP port 1433, then deploying cryptocurrency miners and follow-on tooling. Researchers linked these intrusions to opportunistic campaigns that install customized XMRig miners, use downloader scripts and fileless PowerShell execution, and in some cases deliver Cobalt Strike beacons for persistence and post-compromise control. Investigations also found payload staging through GitHub, abuse of legitimate Windows binaries including MSBuild.exe, rundll32.exe, control.exe, and main.cpl, and injection into trusted processes such as wwanmm.dll to reduce detection.
Threat reports describe Kingminer as a moderately sophisticated criminal botnet that combines public offensive tools with custom malware components, including reflective loading, DLL side-loading, and credential theft capabilities derived from tools such as Mimikatz. In one investigated intrusion, sqlservr.exe launched an obfuscated VBScript that downloaded a standalone PowerShell binary and executed additional scripts in memory before starting a miner. The malware also checked systems for BlueKeep-related hotfixes KB4499175 and KB4500331 and disabled RDP on vulnerable hosts, apparently to block competing botnets from exploiting the same machines. Defenders were advised to enforce strong SQL passwords, restrict internet exposure, patch public-facing services, and improve logging and monitoring, as repeated attack attempts stopped once the underlying weakness was remediated.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Trend Micro’s Managed XDR team investigated a Kingminer attack against a client’s exposed Microsoft SQL Server, tracing an infection chain from sqlservr.exe to obfuscated VBScript, GitHub-hosted PowerShell tooling, in-memory payload execution, and a cryptocurrency miner. The investigation also found BlueKeep hotfix checks and logic to disable RDP on vulnerable legacy Windows systems.
AhnLab ASEC observed a new wave of attacks against publicly exposed Microsoft SQL Servers with weak passwords, where attackers brute-forced access, installed Cobalt Strike, and dropped coin miners including KingMiner, Lemon Duck, and Vollgar. ASEC assessed that the campaign’s download and command-and-control URLs pointed to a single attacker.
Sophos reported that Kingminer was spreading primarily by brute-forcing Microsoft SQL Server credentials, while also experimenting with EternalBlue-based propagation. The report also described the botnet checking for BlueKeep-related patches and disabling RDP on vulnerable hosts to keep competing botnets out.
360 Total Security published research describing a new Kingminer cryptomining trojan variant spreading via weak-password attacks. The reference indicates this reporting occurred in late July 2019.
4 references tracked. Mallory keeps watching after this page renders.
news.sophos.com
Open sourcetrendmicro.com
Open sourcebleepingcomputer.com
Open sourceblog.360totalsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.