Skip to main content

XMRig Covert Ops: The Cryptomining Campaign That Abuses Trusted Access and Deploys Forensic Smokescreens

0
Medium
Published: 07/30/2026 (07/30/2026, 10:18:36 UTC)
Source: AlienVault OTX General

Description

In May 2026, a sophisticated Monero cryptomining campaign was identified targeting Linux environments. Attackers gained initial access through trusted third-party relationships, then escalated to root privileges. Rather than operating openly as root, they weaponized Linux Pluggable Authentication Modules (PAM) to impersonate multiple low-privileged users, creating a forensic smokescreen and establishing redundant persistence through cronjobs. The operators suppressed system logging and deployed a customized XMRig 6.25.0 implant that self-unlinks after execution, running entirely in memory. The binary uses XOR encryption for configuration obfuscation and employs process masquerading to blend with legitimate processes. Campaign tracking revealed operations linked to the V25 Generation 26 family, connecting to the domain unable.download for mining pool communication.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/31/2026, 12:42:54 UTC

Technical Analysis

This threat involves a cryptomining malware campaign targeting Linux environments, leveraging trusted third-party access to gain initial entry and escalate to root privileges. The attackers abuse Linux Pluggable Authentication Modules (PAM) to impersonate multiple low-privileged users, thereby creating a forensic smokescreen and complicating detection. Persistence is maintained through cronjobs. The malware suppresses system logging and deploys a customized version of XMRig 6.25.0 that runs entirely in memory and self-unlinks after execution to avoid forensic artifacts. The binary uses XOR encryption to obfuscate its configuration and employs process masquerading techniques to blend with legitimate processes. The campaign is associated with the V25 Generation 26 malware family and communicates with the domain unable.download for mining pool operations.

Potential Impact

The campaign enables unauthorized cryptomining on compromised Linux systems, leading to resource exhaustion and potential degradation of system performance. The use of PAM abuse and forensic evasion techniques complicates detection and incident response. Root-level access escalation increases the risk of full system compromise and persistent unauthorized control. The in-memory execution and self-unlinking behavior reduce forensic evidence, hindering post-incident analysis.

Defensive Guidance

No official patch or remediation is indicated for this campaign. Since the threat leverages trusted third-party access and PAM abuse, organizations should review and restrict third-party access rights and monitor for unusual PAM activity. Detection efforts should focus on identifying anomalous user impersonation, cronjob persistence, suppressed logging, and process masquerading consistent with XMRig 6.25.0 behavior. Incident response should include verifying the integrity of PAM configurations and scheduled tasks. Patch status is not yet confirmed — check vendor advisories for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.group-ib.com/blog/xmrig-covert-linux-pam-abuse/"]
Pulse Id
6a6b24fc4e9307c078956d75

Indicators of Compromise

Domain

ValueDescriptionCopy
domainunable.download

Hash

ValueDescriptionCopy
hash17b60d650fc5d1718d7f2ac3a6075d11
hash88520bcfc741610591a23592f9d4ecb31e34deb5
hash55c67c844258807c4335f40262777a5307bcf5b537c0492cf869b3328796f838

Threat ID: 6a6c3f149c2644c7f869d16a

Added to database: 07/31/2026, 06:22:12 UTC

Last enriched: 07/31/2026, 12:42:54 UTC

Last updated: 09/14/2026, 09:56:07 UTC

Views: 118

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses