Smominru

Aliases: Ismo

Malware type
botnet, cryptominer, worm
Family
Malware family
Profile updated
2026-07-07 15:12:56

Context

Smominru, also known as Ismo, is a malware family primarily associated with illicit cryptocurrency mining and botnet activities. It propagates using known vulnerabilities to compromise Windows systems globally, often leveraging EternalBlue to rapidly spread across networks.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Smominru_Auto (yara-rule)

Reports & references

  • proofpoint.com — Smominru Monero Mining Botnet Making Millions Operators (report)
  • blog.netlab.360.com — Mykings The Botnet Behind Multiple Active Spreading Botnets (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Smominru (report)

External references