Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware Miner-C

Miner-C

TLP:CLEAR
Family

AI Analysis

· 8 hours ago

Executive Summary

Miner-C deploys Monero‐mining scripts from compromised FTP servers and NAS devices, silently draining CPU cycles from infected machines. Its propagation through file shares broadens its foothold within an organization while remaining difficult to detect without network‑based monitoring.

Enhanced Description

Miner-C is a cryptocurrency‑mining malware that targets Monero (XMR). The software leverages vulnerabilities in FTP servers and exploitation of Network Attached Storage (NAS) devices to inject malicious code, allowing it to spread laterally across an organization’s file systems. Once executed, Miner‑C installs mining scripts that run in the background, drawing CPU resources to generate cryptographic hashes without user consent. Even though the malware’s persistence mechanisms have not been fully documented, analysis indicates it can remain active through scheduled tasks or hidden system services, ensuring continuous operation. The use of FTP and NAS devices for propagation is typical of file‑based dropper approaches: the attacker uploads a malicious archive to an exposed FTP share or a vulnerable NAS web interface, then relies on users or misconfigured machines to execute it. This dual-vector strategy broadens the attack surface and reduces reliance on traditional exploit chains. Operationally, Miner‑C’s impact is primarily measurable in increased CPU utilisation, reduced system performance, and higher bandwidth usage when contacting mining pools. In a networked environment, multiple hosts running the malware can lead to noticeable degradation of shared resources and even compromise compliance with service level agreements.

Key Capabilities

  • Monero cryptocurrency mining
  • Exploits misconfigured FTP servers for initial compromise
  • Propagates via Network Attached Storage (NAS) devices
  • Creates background services or scheduled tasks for persistence
  • Consumes high CPU resources
  • Establishes outbound connections to remote mining pools

ATT&CK Techniques

T1105
T1059
T1136
T1078
T1064

Recommended Actions

  • Block outbound traffic to known Monero mining pool domains and IP ranges.
  • Deploy host‑based intrusion detection that watches for unexpected high CPU usage paired with new background services.
  • Conduct a thorough audit of all FTP servers and NAS devices, patching or disabling insecure protocols.
  • Enable application whitelisting to prevent unauthorized executable execution on client and server systems.
  • Monitor logs for repeated attempts to upload or execute files from untrusted shares.

Suggested Tags

Cryptocurrency Mining
Monero
FTP
NAS
File‑based Propagation
Lateral Movement

Confidence Assessment

The available information about Miner‑C is limited; primary source data cites only its mining activity and its use of FTP/NAS devices. Lack of detailed indicators, sample hashes, and observed persistence mechanisms results in a low confidence rating for the full behavioural profile. Additional evidence from malware labs or incident reports would help refine detection rules.

Description

Miner-C is malware that mines victims for the Monero cryptocurrency. It has targeted FTP servers and Network Attached Storage (NAS) devices to spread. (Citation: Softpedia MinerC)

Details

Type
Malware
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.