CoinMiner Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
6
occurrences
First Seen
November 21, 2025
Last Seen
December 9, 2025

Related Threat Clusters

  • USB-based CoinMiner Malware Targets South Korean Workstations

    CoinMiner malware is being spread through USB drives in South Korea, utilizing malicious shortcut files to execute VBS scripts that deploy BAT malware. This attack campaign aims to compromise workstations by…

    2 articles · Updated December 9, 2025
  • Phishing Campaign Exploits Microsoft Teams Notifications

    A coordinated phishing campaign is targeting Microsoft Teams users by exploiting the platform's notification system. This method allows attackers to bypass traditional security measures, increasing the risk for users…

    5 articles · Updated December 5, 2025
  • CoinMiner Malware Spread via USB Drives Infecting Workstations

    Threat actors are distributing CoinMiner malware through USB drives, targeting workstations. This malware infection can lead to unauthorized cryptocurrency mining, affecting organizational resources. The attack method…

    2 articles · Updated December 5, 2025
  • New Guidance on Risks from Bulletproof Hosting Providers

    Recent guidance has been issued to mitigate risks associated with bulletproof hosting providers, which are often used by cybercriminals to host malicious content. This guidance comes from cybersecurity authorities,…

    7 articles · Updated November 19, 2025
  • Critical Prompt Injection Vulnerability Affects AI in CI/CD Pipelines

    Researchers have identified a critical vulnerability class named 'PromptPwnd' that affects AI agents in GitHub Actions and GitLab CI/CD pipelines. This vulnerability allows attackers to inject malicious prompts through…

    3 articles · Updated December 6, 2025
  • CISA and Global Agencies Address Bulletproof Hosting Cybercrime

    CISA, along with international partners, has released guidance to help internet service providers (ISPs) combat bulletproof hosting (BPH) services that facilitate cybercrime, including ransomware and phishing attacks.…

    3 articles · Updated November 21, 2025

Recent Intelligence Reports

  • USB-based CoinMiner malware delivery persists — Scworld · December 9, 2025
  • Researchers Hack Google's Gemini CLI Through Prompt Injections in GitHub Actions — Cybersecuritynews · December 6, 2025
  • Threat Actors Deploying CoinMiner Malware via USB Drives Infecting Workstations — Cybersecuritynews · December 5, 2025
  • Hackers Exploiting Microsoft Teams Notifications to Deliver CallBack Phishing Attack — Cybersecuritynews · December 5, 2025
  • Threat Actors Distribute CoinMiner Malware through USB Drives to Infect Workstations — Gbhackers · December 5, 2025
  • Cybersecurity Snapshot: Global Agencies Target Criminal “Bulletproof” Hosts, as CSA Unveils Agentic AI Risk Framework — Tenable · November 21, 2025

CVSS v3.1 Breakdown