/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

A new Golang-based worm has been actively dropping XMRig cryptocurrency malware on Windows and Linux servers since early December, mining Monero

Sergiu Gatlan / BleepingComputer :

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

This worm is the latest entry in a long-running Monero-mining lineage that BleepingComputer has tracked for years: the Smominru botnet enslaved over 500,000 mostly-Windows machines via EternalBlue back in 2018, and by 2024 researchers were documenting perfctl hitting millions of Linux servers. What distinguishes this December campaign is its tooling — written in Golang and dropping XMRig on both Windows and Linux from a single codebase.

The economics explain the persistence: an analysis of mining-malware samples found at least 5% of all Monero in circulation was mined by malware, and Monero's privacy features keep payouts hard to trace — which is precisely why operators keep rebuilding the same playbook with new propagation tricks.

First-order effects

  • Windows and Linux server administrators are the immediate targets: any unpatched or weakly configured box can be enlisted to run XMRig, silently converting someone else's compute into Monero and degrading workload performance.

Second-order effects

  • Hosting and cloud providers absorb the knock-on costs — noisy-neighbor CPU contention and abuse tickets — pushing them toward stricter outbound-connection monitoring and miner-detection defaults, while defenders must now watch two OS platforms for one campaign instead of one.

Third-order effects

  • If the pattern holds — Smominru on Windows in 2018, this dual-platform Go worm in 2020, perfctl at Linux scale by 2024 — server-side cryptomining consolidates around cross-platform Golang tooling with Monero as the default payout, making it a durable fixture of the malware economy rather than a price-cycle fad.

The trend: Cryptomining malware is shifting from single-OS botnets to cross-platform Golang worms that treat Windows and Linux servers as interchangeable Monero-mining capacity.

Discussion

  • @arieitan Ari Eitan on x
    New #Golang worm drops XMRig on Windows and Linux servers. FUD in VirusTotal. Targets WebLogic, Tomcat, Jenkins and MySQL using vulns. For example - attempted to exploit WebLogic's CVE-2020-14882. Full IOCs here - https://www.intezer.com/... @AbbyMCH 👏 https://twitter.com/...
  • @schestowitz Dr. Roy Schestowitz on x
    Typical FUD from clueless and/or dishonest media looking to blame “Linux” (or make it look as awful as back-doored Windows) because some admins misconfigure stuff or choose terrible passwords https://www.scmagazine.com/...
  • @adam_k_levin Adam Levin on x
    A newly discovered and self-spreading Golang-based malware has been actively dropping XMRig cryptocurrency miners on Windows and Linux servers since early December. https://www.bleepingcomputer.com/ ...
  • @intezerlabs Intezer on x
    Early bird catches the Golang worm. New #Golang worm drops #XMRigMiner on Windows and Linux servers. Targets public facing services: MySQL, Tomcat, Jenkins and WebLogic. Undetected in VirusTotal https://www.intezer.com/... https://twitter.com/...