On the radar: Weeding out XMRig
ID: 5523eeab-a37d-541b-bb5d-b0a0d39aac7b
STIX ID: report--5523eeab-a37d-541b-bb5d-b0a0d39aac7b
Feed Name: Expel Blog
**TL;DR** Attackers are deploying the XMRig Monero miner across endpoints, cloud instances, and Kubernetes using varied access methods—including CVE-2025-55182 and CVE-2025-66478, compromised credentials, SSH brute force, and commodity malware—and the report outlines detection signals (mining-pool connections, unusual encrypted traffic, sustained high CPU, unexpected scheduled tasks/cron jobs/startup items) and mitigation recommendations (pod security policies, AWS GuardDuty, runtime monitoring).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
