A New Malware Is Hijacking Computers to Secretly Mine Monero (XMR)

2025-7-18 22:00

A dangerous botnet called H2Miner has resurfaced. It hijacks computers to secretly mine Monero (XMR) and, in some cases, deploys ransomware.

Cybersecurity researchers say the malware has expanded since it first appeared in 2019. The new version now targets Linux servers, Windows desktops, and cloud containers.

A Silent Virus Could Be Using Your Computer For Crypto Mining

According to cybersecurity firm Fortinet, attackers gain access by exploiting known software vulnerabilities. These include Log4Shell and Apache ActiveMQ, which many systems still use.

Once inside, the virus installs a tool called XMRig, a legitimate open-source miner. 

But instead of asking for permission, it runs in the background, using your computer’s processing power to earn Monero for the hackers.

Also, H2Miner uses smart scripts to disable antivirus tools. It also kills other miners that may already be running on the system.

Then, it wipes any trace of its actions. On Linux, it installs a cron job that redownloads the malware every 10 minutes. 

On Windows, it sets up a task that runs silently every 15 minutes.

Message From Hackers After Taking Over User Systems. Source: Fortinet A Ransomware Twist Adds More Damage

The virus doesn’t stop at crypto mining. A new payload, called Lcrypt0rx, can also lock up your computer.

It uses a simple but destructive method to overwrite the Master Boot Record—a key part of your computer that controls startup. This can prevent the system from booting properly.

The ransomware also adds fake system settings to hide itself and create persistence.

The campaign takes advantage of cheap cloud servers and misconfigured services. Once a machine is infected, the malware scans for other systems to infect—especially Docker containers and cloud platforms like Alibaba Cloud.

It also spreads through USB drives and loops through antivirus processes, killing them off one by one.

Security experts warn that removing H2Miner requires a deep cleanup. You must delete all related cron jobs, scheduled tasks, and registry entries.

If even one hidden script survives, the botnet can reinstall itself and resume mining Monero in secret.


What Traders and Crypto Users Should Know

This attack isn’t targeting crypto wallets directly. Instead, it steals computing power to generate new Monero coins for the attackers.

The risk is especially high for self-hosted nodes, cloud miners, and unmanaged VPS services.

If your system runs hot or slows down unexpectedly, you might want to check for unusual processes like sysupdate.exe or recurring outbound connections.

Monero’s privacy features make it attractive for attackers. But for users, the real risk is losing control of your devices—and unknowingly funding crypto crime.

The post A New Malware Is Hijacking Computers to Secretly Mine Monero (XMR) appeared first on BeInCrypto.

origin »

Instamine Nuggets (MINE) на Currencies.ru

$ 0 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: 0.00 %
Cегодня L: $0 - H: $0
Капитализация $0 Rank 99999
Доступно / Всего 0 MINE

mine xmr computers monero hijacking new malware

mine xmr → Результатов: 48


Outlaw Hacking Group Updates Toolkit To Mine Monero (XMR) And Kill Off The Competition

The cybersecurity firm Trend Micro says it has detected the Outlaw hacking group has been upgrading its stealing-from-enterprises data kit for about half a year already. Outlaw has been very quiet since June 2019, only to become active again in December, when it started making upgrades to the stealing data kits. It seems now they’re […]

2020-2-12 00:51


Romanian Hackers Get 20 Years in Prison For Cryptojacking 400k Computers To Mine $4M In BTC & XMR

Bogdan Nicolescu, the leader of the Bayrob Group hacker gang from Romania, as well as his co-conspirator Radu Miclaus, have been found guilty of charges related to their cryptojacking malware. The charges include 21 separate counts of wire fraud, money laundering, aggravated identity theft, and other crimes, according to a press release that was published […]

2019-12-10 23:51


Coinmine releases plug-and-play device for mining Ethereum (ETH), Ethereum Classic (ETC), Monero (XMR), and Zcash (ZEC)

Coinmine company is building a plug-and-play mining device, Coinmine One, enabling anyone to mine a host of cryptocurrencies from the comfort of their homes and or offices, The Block reported. The device “provides a new level of accessibility into an otherwise confusing activity, and makes crypto easy for everyone,” according to CoinMine. Coinmine has built […]

2018-11-15 17:19


Фото:

Mining Round-Up: Steam Game Allegedly Cryptojacks Users, Mining Could be “New Oil” for Kazakhstan

In recent mining news, indie Steam game, Abstractism, has been accused of installing malicious software on its users’ devices to mine XMR; the vice president of the Blockchain and Crypto Technology Association of Kazakhstan has advocated that the country’s administration seeks to foster the local mining industry; and the commissioners of the Franklin Public Utility […] The post Mining Round-Up: Steam Game Allegedly Cryptojacks Users, Mining Could be “New Oil” for Kazakhstan appeared first on Bitcoin News.

2018-7-31 02:45


Monero [XMR] mining malware Coinhive takes another victim, League of Legends infected

Players of the popular internet game, League of Legends have fallen prey to a malicious software that programs their system to involuntarily mine Monero [XMR]. A Reddit user named Lestergonzaga discovered this through the Garena server, where many players all around the world have been mining Monero without their knowledge. The mining process took place […]

2018-7-22 02:28