SBRMiner-MULTI is a malware family tracked across 1 threat cluster and 2 intelligence report mentions on ThreatCluster. First observed December 17, 2025; most recent activity December 18, 2025.
SBRMiner-MULTI is a cryptocurrency-mining malware family observed in recent campaigns, with operations attributed to groups such as Crypto crooks co. It targets compromised hosts and cloud accounts (notably AWS) to run mining payloads, reflecting a growing trend of abusing cloud resources for illicit cryptomining and posing risks to both on-premises and cloud environments.
A sophisticated cryptocurrency mining campaign targeting AWS customers began on November 2, 2025, using compromised AWS Identity and Access Management (IAM) credentials. The attackers exploited Amazon Elastic Container…