Threats Tagged 'coinminer'
View all threats tagged with 'coinminer'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'coinminer'
Click on any threat for detailed analysis and mitigation recommendations
Analysis of attacks against Linux SSH servers during Q1 2026 reveals P2PInfect worm as the dominant threat, representing 70.3% of all attack sources. DDoS botnets including Mirai, XMRig, Prometei, and CoinMiner were identified as primary threats. A notable campaign involved installing V2Ray proxy tools on compromised systems, attributed to a suspected Chinese threat actor. Attackers employed SSH brute-force techniques to gain access, executed reconnaissance commands to assess system information, and deployed V2Ray for proxy node operations. The campaign targeted poorly secured SSH servers with weak credentials, emphasizing the need for strong password policies, access controls, and network monitoring to detect unusual outbound connections and proxy-related activities. Join the discussion | AlienVault OTX General | 04/14/2026, 08:54:27 UTC Added: 04/14/2026, 09:32:02 UTC |
During the first quarter of 2026, Windows-based MS-SQL and MySQL database servers experienced consistent malicious attacks with a temporary decrease in February before rising again in March. The primary threat actor, Larva-26002, leveraged various utilities including BCP, curl, bitsadmin, and PowerShell to deploy a Go-based scanner called ICE Cloud, which contained Turkish language strings and C&C-based scanning capabilities. This tool attempted MS-SQL authentication using predefined credentials. Attack methods primarily consisted of brute force attacks, dictionary attacks, and exploitation of unpatched systems with misconfigured accounts stemming from inadequate account management practices. Join the discussion | AlienVault OTX General | 04/14/2026, 08:54:02 UTC Added: 04/14/2026, 09:32:02 UTC |
This intelligence report emphasizes the importance of understanding one's own network environment and not ignoring reconnaissance events in cybersecurity. It highlights the increasing sophistication of bad actors in reconnaissance, both in network scanning and social engineering, aided by AI tools. The report warns against dismissing reconnaissance alerts in favor of focusing solely on attack signals, stressing that initial access brokers excel at understanding target environments. Recent vulnerability discoveries in various software applications are mentioned, along with key security headlines including phishing campaigns, ransomware attacks, and nation-state hacking activities. The report also provides information on prevalent malware files and upcoming security events. MediumMalware Join the discussion | AlienVault OTX General | 01/23/2026, 00:03:21 UTC Added: 01/23/2026, 09:50:56 UTC |
A recent attack on a poorly managed MS-SQL server involved the use of XiebroC2, an open-source C2 framework similar to CobaltStrike. The attackers exploited vulnerable credentials, installed JuicyPotato for privilege escalation, and then deployed XiebroC2 using PowerShell. XiebroC2 supports various features including remote control, information collection, and defense evasion across multiple platforms. The malware collects system information and connects to a C&C server for command execution. To protect against such attacks, administrators are advised to use complex passwords, regularly update them, keep security software current, and implement firewalls to restrict external access to publicly accessible database servers. Join the discussion | AlienVault OTX General | 10/01/2025, 07:36:24 UTC Added: 10/01/2025, 08:49:39 UTC |
The analysis team has categorized attacks on MS-SQL and MySQL servers installed on Windows systems during Q2 2025. While the number of targeted systems remains stable, attacks on MS-SQL servers have been decreasing. MySQL servers saw a significant spike in attacks in June 2025. The report provides detailed statistics on attack trends, including graphs illustrating the attack status for both server types. It also includes a list of MD5 hashes, URLs, FQDNs, and IP addresses associated with the malicious activities. The analysis covers various types of malware and tools used in these attacks, ranging from backdoors and miners to ransomware and remote access trojans. Join the discussion | AlienVault OTX General | 08/08/2025, 17:08:29 UTC Added: 08/08/2025, 21:02:50 UTC |
Showing 1 to 5 of 5 results