GhostMiner
- First seen
- 2018-03-01 00:00:00
- Malware type
- cryptominer
- Family
- Malware family
- Profile updated
- 2026-07-07 14:31:56
Targeted industries: technology-and-telecommunications energy-and-utilities
Context
GhostMiner is a sophisticated cryptocurrency mining malware that employs fileless techniques to evade detection. It primarily targets systems to mine Monero, leveraging PowerShell scripts and process hollowing.
Reports & references
- research.checkpoint.com — Malware Against The C Monoculture (report)
- malpedia.caad.fkie.fraunhofer.de — Ps1.Ghostminer (report)
- blog.minerva-labs.com — Ghostminer Cryptomining Malware Goes Fileless (report)
- Trend Micro — Fileless Cryptocurrency Miner Ghostminer Weaponizes Wmi Objects Kills Other Cryptocurrency Mining Payloads (report)