Malware

xmrig

According to PCrisk, XMRIG is a completely legitimate open-source application that utilizes system CPUs to mine Monero cryptocurrency. Unfortunately, criminals generate revenue by infiltrating this app into systems without users' consent. This deceptive marketing method is called "bundling". In most cases, "bundling" is used to infiltrate several potentially unwanted programs (PUAs) at once. So, there is a high probability that XMRIG Virus came with a number of adware-type applications that deliver intrusive ads and gather sensitive information.

Indicators of Compromise 100

Domain 1710[.]rwlp[.]be Domain a[.]hbweb[.]icu Domain api[.]telegram[.]org Domain borertors92[.]anondns[.]net Domain c[.]hbweb[.]icu Domain cdnjsdelivr[.]beer Domain cmpnst[.]info Domain crazyeltonproxy[.]top Domain d[.]gsocket[.]ninja Domain download[.]sftp-api-group-wechat[.]com Domain g[.]gsocket[.]ninja Domain gitcode[.]com Domain gulf[.]moneroocean[.]stream Domain ip-api[.]com Domain msfconfig[.]icu Domain muckcoding[.]com Domain muckdeveloper[.]com Domain nfdo[.]shop Domain pastebin[.]com Domain pool[.]hashvault[.]pro Domain pool[.]supportxmr[.]com Domain proton66[.]ooo Domain rirosh[.]shop Domain rlim[.]com Domain sekirolegion[.]duckdns[.]org Domain superr[.]buzz Domain t[.]me Domain tele-sync[.]opik[.]net Domain test-steve[.]cyou Domain update-launcher[.]xyz Domain update[.]constant-path[.]xyz Filename /bin/componist Filename /bin/nfdo Filename /bin/rcd Filename /etc/cron.d/apache Filename /tmp/.dbus-cache Filename /tmp/.dbus-cache/gmon Filename /tmp/amd64 Filename /tmp/lte Filename /tmp/mysql Filename /tmp/x86_64 Filename 1.vbs Filename 2.vbs Filename 2022 Filename 3.vbs Filename 4.vbs Filename 4l4md4r Filename 4l4md4r.sh Filename 7zrr.exe Filename DotNetZip.dll Filename FEbJCNWOCKMJ.bat Filename L.ps1 Filename Microsoft.exe Filename MicrosoftEdgeUpdate.exe Filename MicrosoftUpdate.exe Filename NisSrv.exe Filename PyTorchFix.ps1 Filename PythonLauncher-*.lnk Filename STAAAAAS.exe Filename ScreenConnect.Client.exe Filename ScreenConnect.ClientSetup.msi Filename WinRing0x64.sys Filename WindowsServiceHost.vbs Filename WmiPrvSE.exe Filename Wmi_Framework_APIKEY_wmsnet_<random_value>.lnk Filename XMRig Filename ZrvEsJQzWQ.exe Filename alamdar.so Filename api.db Filename dpapimig.exe Filename gs-netcat_mini-linux-x86_64 Filename gsocket.sh Filename hezb.x86_64 Filename libuv-1.dll Filename mgwthmc2.dat Filename putty.exe Filename runner.ps1 Filename system.exe Filename system.txt Filename wmiframework.exe Filename xmrig-C3 GitHub Repo Mash3Do GitHub Repo github.com/LastWer/MicrosoftCur GitHub Repo github.com/kaleidora/dnsub-scanning-tool GitHub Repo github.com/tb78/expresso GitHub Repo lencod GitHub User pepegit666 SHA-256 129de16fe69763f767d8249279a2c4a1a6deafadd1a84563bd84b258ea010bff SHA-256 1505eda3da68e2ff9919b55a31018bd30a991236f041aee835f3bc4e430ce505 SHA-256 1aa4d88a38f5a27a60cfc6d6995f065da074ee340789ed00ddc29abc29ea671e SHA-256 2171deb9293361fd801691948264ad8dc7864935140834449307d040a6d67787 SHA-256 2ac2877c9e4cd7d70673c0643eb16805977a9b8d55b6b2e5a6491db565cee1f SHA-256 4dcae1bddfc3e2cb98eae84e86fb58ec14ea6ef00778ac5974c4ec526d3da31f SHA-256 4e24bbd0fabac6c3efcec943046afbfd332b2c0108a13becfda23a0e26f9ff5f SHA-256 4ea1c577247b149489506b230e7aa203e1a2fa124109c6056d1986e944f520a4 SHA-256 4f11db82193aebe710585b2faefd2b904b6fe6636f7dc25541cea0dd31adada4 SHA-256 4f509762ff7a65e56780f5b1fee10aaed267fe4b15182059480541fc7ce47923 SHA-256 51cada347262d7b2bcde70552fcdae221625ad75435cee8a9c3e7b67cc47a807 SHA-256 5441be217e98051c284d584e830f9a7fc2153143fafee0dc9f6af197cec6c8c9 SHA-256 57e0449fb13766b0b2f7c057b1f89911e9ed23cac7e71d5d69fde47571239629

MITRE ATT&CK TTPs 71

T1003
OS Credential Dumping
Credential Access
T1003.002
Security Account Manager
Credential Access
T1012
Query Registry
Discovery
T1016
System Network Configuration Discovery
Discovery
T1021.002
SMB/Windows Admin Shares
Lateral Movement
T1027
Obfuscated Files or Information
Defense Evasion
T1027.002
Software Packing
Defense Evasion
T1027.003
Steganography
Defense Evasion
T1027.013
Encrypted/Encoded File
Defense Evasion
T1036.005
Match Legitimate Name or Location
Defense Evasion
T1053.003
Cron
Execution
T1053.005
Scheduled Task
Execution
T1055
Process Injection
Defense Evasion
T1055.001
Dynamic-link Library Injection
Defense Evasion
T1056.002
GUI Input Capture
Collection
T1057
Process Discovery
Discovery
T1059
Command and Scripting Interpreter
Execution
T1059.001
PowerShell
Execution
T1060
T1060
T1069
Permission Groups Discovery
Discovery
T1070.004
File Deletion
Defense Evasion
T1071.001
Web Protocols
Command And Control
T1071.004
DNS
Command And Control
T1078
Valid Accounts
Defense Evasion
T1078.001
Default Accounts
Defense Evasion
T1078.004
Cloud Accounts
Defense Evasion
T1082
System Information Discovery
Discovery
T1083
File and Directory Discovery
Discovery
T1085
T1085
T1089
T1089
T1090
Proxy
Command And Control
T1090.004
Domain Fronting
Command And Control
T1095
Non-Application Layer Protocol
Command And Control
T1102.001
Dead Drop Resolver
Command And Control
T1105
Ingress Tool Transfer
Command And Control
T1106
Native API
Execution
T1110
Brute Force
Credential Access
T1110.001
Password Guessing
Credential Access
T1112
Modify Registry
Defense Evasion
T1113
Screen Capture
Collection
T1129
Shared Modules
Execution
T1133
External Remote Services
Persistence
T1135
Network Share Discovery
Discovery
T1140
Deobfuscate/Decode Files or Information
Defense Evasion
T1160
T1160
T1170
T1170
T1190
Exploit Public-Facing Application
Initial Access
T1195.001
Compromise Software Dependencies and Development Tools
Initial Access
T1197
BITS Jobs
Defense Evasion
T1203
Exploitation for Client Execution
Execution
T1204.002
Malicious File
Execution
T1205.001
Port Knocking
Defense Evasion
T1210
Exploitation of Remote Services
Lateral Movement
T1212
Exploitation for Credential Access
Credential Access
T1484.001
Group Policy Modification
Defense Evasion
T1485
Data Destruction
Impact
T1490
Inhibit System Recovery
Impact
T1496
Resource Hijacking
Impact
T1543.001
Launch Agent
Persistence
T1543.002
Systemd Service
Persistence
T1543.003
Windows Service
Persistence
T1548.002
Bypass User Account Control
Privilege Escalation
T1548.004
Elevated Execution with Prompt
Privilege Escalation
T1555.003
Credentials from Web Browsers
Credential Access
T1558
Steal or Forge Kerberos Tickets
Credential Access
T1564.003
Hidden Window
Defense Evasion
T1566
Phishing
Initial Access
T1570
Lateral Tool Transfer
Lateral Movement
T1574.002
DLL Side-Loading
Persistence
T1608.001
Upload Malware
Resource Development
T1685
T1685

Source Articles

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
Cybersecurity firm Huntress identified worm-like activity abusing ConnectWise ScreenConnect to propagate a four-stage VBScript chain across newly connected hosts. The attack uses social engineering, phishing, or fake refund forms to deploy rogue ScreenConnect clients, which then execute a sequence of malicious VBScripts (1.vbs to 4.vbs) for reconnaissance, payload retrieval, and execution. The final stage deploys backdoors, privilege escalation tools, or cryptocurrency miners based on system state, and the infected host re-infects new connections, creating self-propagating behavior. ConnectWise issued an advisory recommending disabling file transfer permissions to mitigate the risk.
hacker-news ·4d ago
The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications
Aeternum is a recently discovered C++ botnet loader that uses the Polygon blockchain for decentralized command-and-control (C2) operations. The malware retrieves encrypted or plaintext instructions from smart contracts on the blockchain by querying public RPC endpoints, enabling resilient and low-cost infrastructure resistant to takedowns. Three distinct malware samples were analyzed: the initial Aeternum loader, a Python-based downloader, and a multi-component payload combining XWorm RAT, XMRig cryptocurrency miner, and data exfiltration tools. The threat leverages Telegram APIs and GitHub repositories for secondary C2 and payload delivery, while using weak encryption schemes that allow decryption via contract address and payload analysis.
unit42 ·4w ago
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
CISA has added seven actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including critical flaws in SonicWall SMA 1000, Sangoma Switchvox, JFrog Artifactory, Kludex Starlette, Kestra OSS, and Berri LiteLLM. Threat actors are exploiting these vulnerabilities to deploy reverse shells, execute arbitrary code, steal credentials, and deploy cryptocurrency miners. Exploitation of CVE-2026-83548 and CVE-2026-83549 in SonicWall devices has been confirmed, while CVE-2026-9586 and CVE-2026-82329 are being used to gain administrative access and conduct post-exploitation activities. Microsoft and Wiz report active exploitation of CVE-2026-42271 and CVE-2026-48710 in LiteLLM deployments, with attackers achieving remote code execution and stealing API keys, and CVE-2026-49869 in Kestra being used to establish reverse shells and deploy miners.
hacker-news ·1w ago
Inside 90 days of attacks on AI infrastructure
Wiz Threat Research observed 90 days of sustained attacks against AI infrastructure through honeypots deployed across services like LiteLLM, Flowise, and LangChain. Attackers exploited vulnerabilities in MCP servers, including authentication bypass and command injection (CVE-2026-59822, CVE-2026-42271), to achieve remote code execution and deploy cryptominers. A second pattern involved blind prompt injection against AI agent frameworks, where attackers used out-of-band DNS callbacks to confirm execution and later fetch payloads from Pastebin. Post-exploitation activity was tailored to AI environments, including in-memory extraction of LiteLLM master keys, model enumeration, and use of environment-specific camouflage to hide malicious binaries.
wiz
After the Break-In: What Attackers Do Once They're Already Inside
Huntress investigated a real-world incident in June 2026 where an attacker gained initial access via a SQL injection vulnerability on a web server. After entry, the attacker conducted reconnaissance, created a backdoor user, enabled Remote Desktop, disabled Windows Defender, and deployed multiple payloads including the BadIIS malware and the XMRig cryptocurrency miner. The attacker used PowerShell scripts to maintain persistence and evade detection, highlighting the importance of not only removing malware but also identifying and patching the initial vulnerability to prevent reinfection.
bleeping-computer ·1mo ago
Steam forum ClickFix attacks infect gamers with XMRig cryptominers
Threat actors are exploiting Steam discussion forums in a social engineering campaign known as ClickFix, where they pose as helpful users offering technical fixes. They trick victims into running malicious PowerShell commands that download and execute an XMRig cryptominer. The script masquerades as a Windows optimization tool, performs fake maintenance tasks, and establishes persistence via scheduled tasks and Defender exclusions, ultimately leading to cryptocurrency mining on compromised systems.
bleeping-computer ·1mo ago
RedisRaider: Weaponizing misconfigured Redis to mine cryptocurrency at scale | Datadog Security Labs
RedisRaider is a Linux cryptojacking campaign that targets publicly exposed Redis servers to deploy a custom XMRig miner. The threat actor uses aggressive scanning, obfuscation techniques, and cron job manipulation to propagate and maintain persistence. The campaign also leverages in-browser mining infrastructure, indicating a multi-pronged monetization strategy. Anti-forensics measures such as short-lived Redis keys and configuration tampering are used to evade detection.
static-urls
The gift that keeps on giving: A new opportunistic Log4j campaign | Datadog Security Labs
A new opportunistic campaign exploiting the Log4Shell vulnerability (CVE-2021-44228) has been observed targeting vulnerable Java applications. The attack uses obfuscated LDAP requests to deliver a malicious Java class, which downloads and executes a crypto-mining payload (XMRig) and establishes persistence via systemd or cron. The threat actor exfiltrates system information and maintains remote access through encrypted reverse shells using Perl and netcat.
Datadog Security Labs
Beyond Mimo’lette: Tracking Mimo's Expansion to Magento CMS and Docker | Datadog Security Labs
The Mimo threat actor, previously known for targeting Craft CMS, has expanded its operations to compromise Magento CMS platforms and misconfigured Docker instances through PHP-FPM vulnerabilities. The actor employs sophisticated persistence and evasion techniques, including GSocket-based reverse shells, in-memory execution via memfd_create(), and process masquerading to mimic kernel threads. Mimo monetizes compromised systems through cryptojacking using XMRig and proxyjacking via IPRoyal Pawns, indicating a dual revenue strategy. This evolution reflects increased operational sophistication and a broader targeting scope beyond CMS platforms.
Datadog Security Labs
Malicious Go Module Exposes GitHub Malware Lure Network Spanning 222 Repositories
A malicious Go module, github.com/kaleidora/dnsub-scanning-tool, serves as a lure to deliver a multi-stage Windows malware chain involving hidden PowerShell execution and encrypted payload resolution via public dead drops. The campaign, tracked as Operation Muck and Load, leverages a network of 222 GitHub repositories across 190 accounts to create credibility and scale for malicious or deceptive software projects. These repositories use synthetic activity to appear recently maintained, facilitating social engineering and malware distribution. The final payload includes RATs such as AsyncRAT, Quasar, and Remcos, along with infostealers like Vidar, enabling credential theft, screen capture, and persistence.
socket-dev