xmrig

Malware type
cryptominer
Family
Malware family
Last IoC activity
2026-07-22 04:04:50
Profile updated
2026-07-07 13:07:57

Context

According to PCrisk, XMRIG is a completely legitimate open-source application that utilizes system CPUs to mine Monero cryptocurrency. Unfortunately, criminals generate revenue by infiltrating this app into systems without users' consent. This deceptive marketing method is called "bundling". In most cases, "bundling" is used to infiltrate several potentially unwanted programs (PUAs) at once. So, there is a high probability that XMRIG Virus came with a number of adware-type applications that deliver intrusive ads and gather sensitive information.

Detection coverage

  • 3 YARA rules

Used by threat actors

  • AWS Fargate Cryptojacking Activity (campaign)
  • Iranian APT Credential Harvesting & Cryptomining Activity (campaign)

Detection rules

  • SEKOIA_Miner_Win_Xmrig_Strings (yara-rule)
  • SEKOIA_Miner_Lin_Xmrig_Strings (yara-rule)
  • SIGNATURE_BASE_PUA_WIN_XMRIG_Cryptocoin_Miner_Dec20 (yara-rule)

Reports & references

  • CrowdStrike — New Kiss A Dog Cryptojacking Campaign Targets Docker And Kubernetes (report)
  • akamai.com — 2024 Php Exploit Cve One Day After Disclosure (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Xmrig (report)
  • gridinsoft.com — Xmrig (report)
  • harfanglab.io — Unpacking Packxor (report)

External references