ELF CoinMiner (also known as XMRig variants, Linux miners) is a linux malware active since Ongoing. Linux cryptocurrency mining malware. Key characteristics include: Monero mining, SSH brute force propagation, cron persistence, container targeting.
Overview & Background
Linux cryptocurrency mining malware. First identified in Ongoing, this threat is attributed to eCrime.
ELF CoinMiner remains an active threat. Organizations should implement detection rules and monitor for indicators associated with this linux malware.
- Category: Linux Malware
- Active since: Ongoing
- Attribution: eCrime
- Also known as: XMRig variants, Linux miners
Technical Analysis
ELF CoinMiner employs the following capabilities and techniques:
- Monero Mining: Core functionality
- Ssh Brute Force Propagation: Core functionality
- Cron Persistence: Core functionality
- Container Targeting: Core functionality
MITRE ATT&CK Mapping
| Tactic | Technique | Usage |
|---|---|---|
| Initial Access | T1566.001 Phishing Attachment | Common delivery vector |
| Execution | T1204.002 Malicious File | User-triggered execution |
| Persistence | T1547.001 Registry Run Keys | Autostart persistence |
| Defense Evasion | T1027 Obfuscated Files | Payload obfuscation |
| C2 | T1071.001 Web Protocols | HTTP/HTTPS C2 |
Detection & Defense
- Endpoint detection: Deploy behavioral detection rules for ELF CoinMiner indicators
- Network monitoring: Monitor for C2 traffic patterns and anomalous connections
- Threat intelligence: Track ELF CoinMiner IOCs and campaign updates
- Security awareness: Train users to recognize phishing and social engineering
- Patch management: Keep systems updated to prevent exploitation
Defend Against ELF CoinMiner
Mjolnir Security provides detection and response capabilities against ELF CoinMiner and similar threats.
- Proactive Threat Hunting Hunt for ELF CoinMiner indicators and TTPs within your environment.
- Threat Intelligence Monitor ELF CoinMiner campaigns and infrastructure changes.
- 24/7 Incident Response Rapid containment and forensic investigation. Call +1 833 403 5875.
Stay ahead of emerging threats. Get notified when we publish new intelligence reports and advisories.
Subscribe to Alerts