LoudMiner

MITRE ATT&CK: S0451 View on attack.mitre.org

Aliases: LoudMiner

First seen
2019-06-01 00:00:00
Malware type
cryptominer
Family
Malware family
Operating systems
macos, windows
Profile updated
2026-07-07 15:30:22

Targeted industries: media-and-entertainment

Context

LoudMiner is a cryptocurrency miner which uses virtualization software to siphon system resources. The miner has been bundled with pirated copies of Virtual Studio Technology (VST) for Windows and macOS.

Detection coverage

  • 280 Sigma rules

Malware & tools used

  • Process Discovery (attack-pattern)
  • Launchctl (attack-pattern)
  • Command Obfuscation (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Hidden Files and Directories (attack-pattern)
  • Unix Shell (attack-pattern)
  • Launch Daemon (attack-pattern)
  • Compute Hijacking (attack-pattern)
  • Windows Service (attack-pattern)
  • Drive-by Compromise (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Service Execution (attack-pattern)
  • File Deletion (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Run Virtual Instance (attack-pattern)
  • Msiexec (attack-pattern)
  • Windows Command Shell (attack-pattern)

Reports & references

  • MITRE ATT&CK — S0451 (report)
  • ESET — Loudminer Mining Cracked Vst Software (report)

External references