Researchers detail Smominru, a Monero cryptocurrency mining botnet using NSA's EternalBlue exploit to enslave 500K+ computers, mostly targeting Windows servers
The Smominru miner has infected at least half a million machines — mostly consisting of Windows servers — and spreads using the EternalBlue exploit.
Context & Ripple Effects
Smominru is the second confirmed large-scale abuse of EternalBlue after WannaCry: researchers had already traced an earlier, possibly bigger campaign to the same NSA exploit, which installed the Adylkuzz cryptocurrency miner months before ransomware made the vulnerability famous. The pattern is consistent — leaked exploit code repurposed not for extortion but for quietly converting other people's servers into mining infrastructure.
First-order effects
- Over 500,000 machines, mostly Windows servers, are now doing unauthorized work for the botnet's operators — their owners pay the electricity and hardware wear while Smominru collects Monero.
Second-order effects
- Every unpatched Windows server becomes a contested resource: defenders race to apply patches while rival mining worms compete for the same vulnerable fleet, a dynamic later seen when a Golang-based worm began dropping XMRig miners on Windows and Linux servers.
Third-order effects
- Monero's privacy properties make it the recurring payout of choice for server malware — an analysis found at least 5% of all Monero in circulation was mined by malware — and the playbook has since migrated to Linux at scale with perfctl targeting millions of servers, suggesting cryptojacking is a durable business model rather than a passing fad tied to any single exploit.
The trend: Server-focused cryptocurrency mining malware keeps regenerating around new exploits and platforms, with Monero as the constant payout and unpatched enterprise servers as the constant target.