logo

Use of XMRig Cryptominer by Threat Actors Expanding: Expel

ID: 0f834361-6c9c-5af0-9779-5b42aa8224b6

STIX ID: report--0f834361-6c9c-5af0-9779-5b42aa8224b6

Feed Name: Security Boulevard

Threat Score
65/100

Date Published: 2026-01-09

Date Updated: 2026-04-22

Author: Jeffrey Burt

...
...

The report describes a resurgence of XMRig cryptominer abuse: actors have distributed XMRig via game torrents and exploited the high-severity React2Shell vulnerability to deploy both packed and standard XMRig across endpoints, Kubernetes pods, and AWS EC2 instances; security vendors recommend monitoring for unusual CPU usage, outbound connections to Monero pools, unexpected scheduled tasks/cron jobs, and hardening cloud/pod configurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.