A new Golang-based worm has been actively dropping XMRig cryptocurrency malware on Windows and Linux servers since early December, mining Monero
Sergiu Gatlan / BleepingComputer :
Context & Ripple Effects
This worm is the latest entry in a long-running Monero-mining lineage that BleepingComputer has tracked for years: the Smominru botnet enslaved over 500,000 mostly-Windows machines via EternalBlue back in 2018, and by 2024 researchers were documenting perfctl hitting millions of Linux servers. What distinguishes this December campaign is its tooling — written in Golang and dropping XMRig on both Windows and Linux from a single codebase.
The economics explain the persistence: an analysis of mining-malware samples found at least 5% of all Monero in circulation was mined by malware, and Monero's privacy features keep payouts hard to trace — which is precisely why operators keep rebuilding the same playbook with new propagation tricks.
First-order effects
- Windows and Linux server administrators are the immediate targets: any unpatched or weakly configured box can be enlisted to run XMRig, silently converting someone else's compute into Monero and degrading workload performance.
Second-order effects
- Hosting and cloud providers absorb the knock-on costs — noisy-neighbor CPU contention and abuse tickets — pushing them toward stricter outbound-connection monitoring and miner-detection defaults, while defenders must now watch two OS platforms for one campaign instead of one.
Third-order effects
- If the pattern holds — Smominru on Windows in 2018, this dual-platform Go worm in 2020, perfctl at Linux scale by 2024 — server-side cryptomining consolidates around cross-platform Golang tooling with Monero as the default payout, making it a durable fixture of the malware economy rather than a price-cycle fad.
The trend: Cryptomining malware is shifting from single-OS botnets to cross-platform Golang worms that treat Windows and Linux servers as interchangeable Monero-mining capacity.