logo

On the radar: Weeding out XMRig

ID: 5523eeab-a37d-541b-bb5d-b0a0d39aac7b

STIX ID: report--5523eeab-a37d-541b-bb5d-b0a0d39aac7b

Feed Name: Expel Blog

Threat Score
60/100

Date Published: 2026-01-07

Date Updated: 2026-04-27

Author: Ben Nahorney

...
...

**TL;DR** Attackers are deploying the XMRig Monero miner across endpoints, cloud instances, and Kubernetes using varied access methods—including CVE-2025-55182 and CVE-2025-66478, compromised credentials, SSH brute force, and commodity malware—and the report outlines detection signals (mining-pool connections, unusual encrypted traffic, sustained high CPU, unexpected scheduled tasks/cron jobs/startup items) and mitigation recommendations (pod security policies, AWS GuardDuty, runtime monitoring).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.