logo

Massive Botnet Turns Windows Machines into Miners

ID: 9dc5296e-a9b4-5693-b87a-01f36aa7334b

STIX ID: report--9dc5296e-a9b4-5693-b87a-01f36aa7334b

Feed Name: Binary Defense Blog

Threat Score
80/100

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

Researchers discovered the Smominru botnet that compromised over half a million Windows devices using the EternalBlue exploit (and EsteemAudit against RDP on legacy systems) to deploy Monero miners; it has mined approximately 8,900 XMR (~$2.8M–$3.6M). The botnet exhibits worm-like propagation, can regenerate after partial takedowns, and is concentrated in Russia, India, and Taiwan, though the operators remain unidentified.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.