Coinminer

Malware type
cryptominer
Family
Malware family
Last IoC activity
2026-07-21 02:31:10
Profile updated
2026-07-07 14:43:04

Context

Coinminer is an unwanted malicious software which uses the victim's computational power (CPU and RAM mostly) to mine for coins (for example Monero or Zcash). The malware achieves persistence by adding one of the opensource miners on startup without the victim's consensus. Most sophisticated coin miners use timer settings or cap the CPU usage in order to remain stealthy.

Detection coverage

  • 2 YARA rules

Detection rules

  • MALPEDIA_Win_Coinminer_Auto (yara-rule)
  • TRELLIX_ARC_Trojan_Coinminer (yara-rule)

Reports & references

  • blog.sekoia.io — Privateloader The Loader Of The Prevalent Ruzki Ppi Service (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Coinminer (report)
  • secrary.com — Coinminer (report)
  • blog.malwarebytes.com — A Coin Miner With A Heavens Gate (report)
  • triskelelabs.com — Investigating Monero Coin Miner (report)
  • Cisco Talos — Modernloader Delivers Multiple Stealers (report)
  • blog.malwarebytes.com — Amp (report)
  • thedfirreport.com — All That For A Coinminer (report)

External references