Monero Miner

Aliases: CoinMiner

First seen
2017-05-26 00:00:00
Malware type
cryptominer
Family
Malware family
Last IoC activity
2026-07-22 02:43:23
Profile updated
2026-07-07 14:22:52

Context

According to ESET, first seen in-the-wild on 26th May, 2017, the malicious mining software is a fork of a legitimate open source Monero CPU miner called xmrig.

Detection coverage

  • 2 YARA rules

Detection rules

  • TRELLIX_ARC_Trojan_Coinminer (yara-rule)
  • MALPEDIA_Win_Coinminer_Auto (yara-rule)

Reports & references

  • cybersecurity.att.com — Shikitega New Stealthy Malware Targeting Linux (report)
  • thedfirreport.com — All That For A Coinminer (report)
  • news.sophos.com — Node Poisoning Hijacked Package Delivers Coin Miner And Credential Stealing Backdoor (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Monero Miner (report)
  • asec.ahnlab.com — 37526 (report)
  • ESET — Monero Money Mining Malware (report)

External references