Malware

Monero Miner

Also known as: CoinMiner

According to ESET, first seen in-the-wild on 26th May, 2017, the malicious mining software is a fork of a legitimate open source Monero CPU miner called xmrig.

MITRE ATT&CK TTPs 7

Source Articles

Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner
A critical authentication vulnerability in Apple macOS Screen Sharing, tracked as CVE-2026-65400 (CVSS 9.8), is under active exploitation to deploy Monero cryptominers on internet-exposed Mac systems. The flaw allows unauthorized remote authentication to the Screen Sharing service without valid credentials, enabling attackers to gain root access and install malware. The Netherlands NCSC reported confirmed attacks where systems with port 5900 exposed were compromised. Apple has released emergency patches in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. A separate but related pre-authentication flaw in the same component was also patched, both residing in the same codebase and exploitable with minimal effort.
hacker-news ·2w ago
Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
The Netherlands' National Cyber Security Centre (NCSC) has issued a warning that attackers are actively exploiting a macOS Screen Sharing vulnerability, CVE-2026-65400, to gain unauthorized access to systems with exposed port 5900. The flaw allows network-based attackers to bypass authentication and obtain root access without valid credentials. In confirmed attacks, the threat actors have deployed Monero cryptocurrency miners on compromised systems. Apple has patched the vulnerability in recent macOS updates, including Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.
bleeping-computer ·2w ago