Monero Miner
Aliases: CoinMiner
- First seen
- 2017-05-26 00:00:00
- Malware type
- cryptominer
- Family
- Malware family
- Last IoC activity
- 2026-07-22 02:43:23
- Profile updated
- 2026-07-07 14:22:52
Context
According to ESET, first seen in-the-wild on 26th May, 2017, the malicious mining software is a fork of a legitimate open source Monero CPU miner called xmrig.
Detection coverage
- 2 YARA rules
Detection rules
- TRELLIX_ARC_Trojan_Coinminer (yara-rule)
- MALPEDIA_Win_Coinminer_Auto (yara-rule)
Reports & references
- cybersecurity.att.com — Shikitega New Stealthy Malware Targeting Linux (report)
- thedfirreport.com — All That For A Coinminer (report)
- news.sophos.com — Node Poisoning Hijacked Package Delivers Coin Miner And Credential Stealing Backdoor (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Monero Miner (report)
- asec.ahnlab.com — 37526 (report)
- ESET — Monero Money Mining Malware (report)