xmrig
- Malware type
- cryptominer
- Family
- Malware family
- Last IoC activity
- 2026-07-22 04:04:50
- Profile updated
- 2026-07-07 13:07:57
Context
According to PCrisk, XMRIG is a completely legitimate open-source application that utilizes system CPUs to mine Monero cryptocurrency. Unfortunately, criminals generate revenue by infiltrating this app into systems without users' consent. This deceptive marketing method is called "bundling". In most cases, "bundling" is used to infiltrate several potentially unwanted programs (PUAs) at once. So, there is a high probability that XMRIG Virus came with a number of adware-type applications that deliver intrusive ads and gather sensitive information.
Detection coverage
- 3 YARA rules
Used by threat actors
- AWS Fargate Cryptojacking Activity (campaign)
- Iranian APT Credential Harvesting & Cryptomining Activity (campaign)
Detection rules
- SEKOIA_Miner_Win_Xmrig_Strings (yara-rule)
- SEKOIA_Miner_Lin_Xmrig_Strings (yara-rule)
- SIGNATURE_BASE_PUA_WIN_XMRIG_Cryptocoin_Miner_Dec20 (yara-rule)
Reports & references
- CrowdStrike — New Kiss A Dog Cryptojacking Campaign Targets Docker And Kubernetes (report)
- akamai.com — 2024 Php Exploit Cve One Day After Disclosure (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Xmrig (report)
- gridinsoft.com — Xmrig (report)
- harfanglab.io — Unpacking Packxor (report)