logo

Threat Advisory: XMRig Cryptomining By Way Of TeamViewer

ID: 19706c16-a0e6-5ef3-b6c1-51d00603e6b8

STIX ID: report--19706c16-a0e6-5ef3-b6c1-51d00603e6b8

Feed Name: Huntress Blog

Threat Score
50/100

Date Published: 2024-02-03

Date Updated: 2026-04-28

...
...

Huntress SOC investigated a series of XMRig cryptocurrency miner infections discovered in May 2023 where attackers gained initial access via compromised TeamViewer credentials, used clipboard and PowerShell/batch scripts to download and execute a miner payload from domains hosted on OSS-accelerate and other locations, and persisted via a Windows service; the report includes timelines reconstructed from EDR and Windows event logs, IOCs (malicious domains and wallet), MITRE ATT&CK mappings, and a high-fidelity EQL detection to identify similar infections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.