Threats Tagged 'monero'
View all threats tagged with 'monero'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'monero'
Click on any threat for detailed analysis and mitigation recommendations
An exposed directory at 188.245.99.156 revealed a comprehensive cryptomining toolkit containing 147 files including Python exploit source code, campaign logs, and Windows registry hives. Analysis confirms 3,562 Redis servers were compromised across two campaign runs targeting 12,966 hosts. The operation exploited unauthenticated Redis instances using rogue replication techniques to inject cron jobs that deployed XMRig miners. Victims spanned Redis versions 2.8.17 through 7.2.0 across outdated and current Linux distributions, indicating misconfiguration rather than version-specific vulnerabilities. The toolkit also targeted WordPress, MongoDB, and SSH but achieved zero confirmed compromises through those vectors. A separate February 2026 open directory linked by wallet reuse revealed Meterpreter deployment capabilities, extending the operator's known activity timeline by five months. The operation mined Monero through pool.moneroocean.stream with the same wallet used on the operator's own Windows-based work... Join the discussion | AlienVault OTX General | 09/08/2026, 16:59:09 UTC Added: 09/09/2026, 09:22:16 UTC |
In May 2026, a sophisticated Monero cryptomining campaign was identified targeting Linux environments. Attackers gained initial access through trusted third-party relationships, then escalated to root privileges. Rather than operating openly as root, they weaponized Linux Pluggable Authentication Modules (PAM) to impersonate multiple low-privileged users, creating a forensic smokescreen and establishing redundant persistence through cronjobs. The operators suppressed system logging and deployed a customized XMRig 6.25.0 implant that self-unlinks after execution, running entirely in memory. The binary uses XOR encryption for configuration obfuscation and employs process masquerading to blend with legitimate processes. Campaign tracking revealed operations linked to the V25 Generation 26 family, connecting to the domain unable.download for mining pool communication. Join the discussion | AlienVault OTX General | 07/30/2026, 10:18:36 UTC Added: 07/31/2026, 06:22:12 UTC |
The article discusses the evolution of cryptojacking, from its rise with Coinhive in 2017 to its apparent decline and subsequent resurgence in a more sophisticated form. A new campaign was discovered involving over 3,500 infected websites, using stealthy techniques to mine cryptocurrency without detection. The modern approach involves dropper scripts, environment checks, worker spawning, and C2 communication, prioritizing stealth over resource consumption. This new wave of cryptojacking attacks demonstrates the ongoing cat-and-mouse game between attackers and security measures, highlighting the need for continued vigilance in cybersecurity. Join the discussion | AlienVault OTX General | 08/20/2025, 10:50:59 UTC Added: 08/20/2025, 12:02:47 UTC |
A new Android malware campaign has been discovered, disguising itself as a banking app to covertly mine cryptocurrency on locked devices. The malware, distributed through a phishing website impersonating Axis Bank, downloads and executes a modified version of XMRig, a popular cryptocurrency mining software. It monitors the device's lock state and battery level, initiating mining operations when the device is locked and stopping when unlocked. This stealthy approach allows for persistent mining, leading to excessive heat generation, battery drain, and potential hardware damage. The malware uses multiple hosting platforms to distribute its payload and connects to specific mining pools. Its impact on devices includes high CPU and memory usage, significant temperature increases, and overall performance degradation. Join the discussion | AlienVault OTX General | 07/18/2025, 13:03:31 UTC Added: 07/18/2025, 20:30:58 UTC |
A resurgence of malware deploying XMRig cryptominer was discovered in mid-April 2025, coinciding with a rally in Monero cryptocurrency value. The malware uses a multi-staged approach and LOLBAS techniques, leveraging Windows tools like PowerShell for payload delivery, detection evasion, and persistence. The attack chain involves three stages: initial infection via a batch file, persistence establishment, and cryptomining execution. The malware targets diverse countries, including Russia, Belgium, Greece, and China. It disables Windows Update services, evades Windows Defender, and uses scheduled tasks for persistence. The XMRig miner creates registry entries and drops files for continued operation. Despite its simple, unobfuscated nature, the malware proved effective in avoiding detection. Join the discussion | AlienVault OTX General | 07/07/2025, 13:55:35 UTC Added: 07/07/2025, 21:09:24 UTC |
Showing 1 to 5 of 5 results