Skip to content
September 28, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Malware
  • Researcher: 5% of the Monero currency were dug out by Malicious Monero Miners
  • Malware

Researcher: 5% of the Monero currency were dug out by Malicious Monero Miners

Do Son June 17, 2018 3 minutes read
Add Daily CyberSecurity as a preferred source on Google

A researcher at Palo Alto Networks, Josh Grunzweig published “The Rise of the Cryptocurrency Miners” article. According to the data collected by the company’s WildFire platform, the number of cryptocurrency mining malware samples has maintained a rapid increase since 2017. This means that illegal cryptocurrency mining is becoming a new type of cyber threat, and more and more cyber attacks have begun to tend to exploit the cryptocurrency to mine malware.

The following figure shows how many new cryptocurrency mining malware samples have been identified over time. But it is worth mentioning that this data does not represent all of them, which does not include JavaScript or web-based malicious mining activities, and these activities are also continuing to plague every Internet user.

Starting around June 2017, the prices of Bitcoin and other popular cryptocurrencies have risen sharply, and more and more people are trying to invest, eventually pushing prices higher. Coincidentally, in June 2017, the Unit 42 team also witnessed a surge in the number of cryptocurrency mining malware in the WildFire platform.

This sharp rise in prices peaked in December 2017, when Bitcoin’s rate rose to nearly $20,000. Its price has now dropped back to around $8,000.

So far, about 470,000 unique samples have been confirmed. According to Grunzweig, most of the cyberattack activities delivered cryptocurrency mining malware targeted at Monero (about 84.5%).

As mentioned above, Grunzweig extracted 2,341 Monero wallets from the analysed sample set. Unlike some other cryptocurrencies, Grunzweig stated that it is not possible to retrieve the current balance of a single wallet by querying the Monero blockchain without an owner’s password. This is due to the original design of the Monero currency.

Grunzweig, therefore, adopted a different method to determine how much money the attacker earned—a mining pool based on mining operations. By looking at the top ten mining pools used by malware, Grunzweig stated that in addition to one, the rest of the mining pools allowed anonymous viewing of statistics based on wallets as identifiers.

Grunzweig eventually inquired about the top eight mining pools used by all 2,341 Monero wallets. By querying the mining pool itself (rather than the blockchain), he can accurately determine how much Monero has historically mined, without worrying about data being contaminated by other sources.

So far, the popularity of illegal cryptocurrency mining activities has continued to soar. The soaring of such events can be said to be a direct result of the previous sharp increase in cryptocurrency prices, and the current trend of prices is falling and stabilising. With this trend, only time can tell whether the cryptocurrency mining malware will continue to be famous. Such activities are very profitable for individuals or groups who use malicious technology to make long-term exploitation of cryptocurrency. Historically, the total value of Monroe coins discovered through malicious software has reached 175 million U.S. dollars and accounts for 5% of the total number of Monroe coins currently on the market.

To completely block the delivery of cryptocurrency mining malware through cyberattack activities is a daunting task, as many malware developers limit CPU usage or ensure that the mining operation is only at certain times of the day, or when the user is inactive. Also, the malware itself is delivered through some different methods, which requires defenders to have a broader approach to security.

Source, Image: paloaltonetworks

Related coverage

  • Tax Extension Malware Campaign Exploits Trusted GitHub Repositories to Deliver Remcos RAT
  • Thousands of SonicWall Devices Remain Vulnerable to CVE-2024-40766
  • Malware Disguised as SteamCleaner Uses Valid Signature to Inject Node.js RCE Backdoor
  • Iranian Hacker Group MuddyWater Abuses Legitimate Atera Software to Target Global Organizations
  • North Korean APT Lazarus Uses Malicious npm Package to Target Developers
  • VanHelsingRaaS: A New Player in the Ransomware Game
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.

We respect your inbox. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Malicious Monero Miners

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-88771
    Remote code execution due to improper input validation that can allow an unauthenticated attacker to execute arbitrary commands.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-65660CVSS 8.8
    Improper control of generation of code (\'code injection\') in Microsoft Office SharePoint allows an authorized attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 25, 2026
  • CVE-2026-5430CVSS 10.0
    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-71362CVSS 9.1
    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-48842CVSS 8.1
    Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-87902
    Unauthenticated path traversal in page-template resolution leading to conditional RCE An unauthenticated attacker can make get_page_template() page-template resolution...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 23, 2026
  • CVE-2026-94127CVSS 9.8
    When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-20192CVSS 10.0
    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE)...
    📅 Updated: Sep 28, 2026
  • CVE-2026-101039CVSS 10.0
    A vulnerability was identified in FAST FAC1900R 20190827_2.0.2. Affected by this issue is the function copy_msg_element of the...
    📅 Updated: Sep 28, 2026
  • CVE-2026-88771CVSS 9.5
    Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37,...
    CISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 28, 2026
  • CVE-2026-101001CVSS 10.0
    A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This impacts the function eval of the file /www/cgi-bin/network_tools of...
    📅 Updated: Sep 28, 2026
  • CVE-2026-101007CVSS 9.3
    A vulnerability has been found in aaPanel BaoTa up to 11.8.0. This issue affects the function InputSql of...
    📅 Updated: Sep 28, 2026
  • CVE-2026-101038CVSS 9.4
    A vulnerability was determined in FAST FAC1200R 5.0_20201119_1.0.2. Affected by this vulnerability is the function MmtAtePrase of the...
    📅 Updated: Sep 28, 2026
  • CVE-2026-81867CVSS 9.4
    A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application Integration versions prior to...
    📅 Updated: Sep 28, 2026
  • CVE-2026-19759CVSS 9.4
    An Incorrect Authorization vulnerability in the task configuration in Google Cloud Application Integration versions prior to 2026-06-17 on Google...
    📅 Updated: Sep 28, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.