LoudMiner
MITRE ATT&CK: S0451 View on attack.mitre.org
Aliases: LoudMiner
- First seen
- 2019-06-01 00:00:00
- Malware type
- cryptominer
- Family
- Malware family
- Operating systems
- macos, windows
- Profile updated
- 2026-07-07 15:30:22
Targeted industries: media-and-entertainment
Context
LoudMiner is a cryptocurrency miner which uses virtualization software to siphon system resources. The miner has been bundled with pirated copies of Virtual Studio Technology (VST) for Windows and macOS.
Detection coverage
- 280 Sigma rules
Malware & tools used
- Process Discovery (attack-pattern)
- Launchctl (attack-pattern)
- Command Obfuscation (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Hidden Files and Directories (attack-pattern)
- Unix Shell (attack-pattern)
- Launch Daemon (attack-pattern)
- Compute Hijacking (attack-pattern)
- Windows Service (attack-pattern)
- Drive-by Compromise (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Service Execution (attack-pattern)
- File Deletion (attack-pattern)
- System Information Discovery (attack-pattern)
- Run Virtual Instance (attack-pattern)
- Msiexec (attack-pattern)
- Windows Command Shell (attack-pattern)
Reports & references
- MITRE ATT&CK — S0451 (report)
- ESET — Loudminer Mining Cracked Vst Software (report)