Coinminer
- Malware type
- cryptominer
- Family
- Malware family
- Last IoC activity
- 2026-07-21 02:31:10
- Profile updated
- 2026-07-07 14:43:04
Context
Coinminer is an unwanted malicious software which uses the victim's computational power (CPU and RAM mostly) to mine for coins (for example Monero or Zcash). The malware achieves persistence by adding one of the opensource miners on startup without the victim's consensus. Most sophisticated coin miners use timer settings or cap the CPU usage in order to remain stealthy.
Detection coverage
- 2 YARA rules
Detection rules
- MALPEDIA_Win_Coinminer_Auto (yara-rule)
- TRELLIX_ARC_Trojan_Coinminer (yara-rule)
Reports & references
- blog.sekoia.io — Privateloader The Loader Of The Prevalent Ruzki Ppi Service (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Coinminer (report)
- secrary.com — Coinminer (report)
- blog.malwarebytes.com — A Coin Miner With A Heavens Gate (report)
- triskelelabs.com — Investigating Monero Coin Miner (report)
- Cisco Talos — Modernloader Delivers Multiple Stealers (report)
- blog.malwarebytes.com — Amp (report)
- thedfirreport.com — All That For A Coinminer (report)