|

Well-known Monero mining malware modified to steal user data

  • Malware program “Smominru” had been modified to “steal system access information for possible sale on the dark web.”
  • This malware has already infected half a million computers.

Monero (XMR), the privacy-oriented cryptocurrency, has been plagued by mining malware issues again. Carbon Black, an online security firm, revealed in a report that its Threat Analysis Unit found “a secondary component” in a well-known malware program called “Smominru.” The malware script had been modified to “steal system access information for possible sale on the dark web.” This malware has already infected half a million computers.

According to the researchers:

“This discovery indicates a bigger trend of commodity malware evolving to mask a darker purpose and will force a change in the way cybersecurity professionals classify, investigate and protect themselves from threats.”

Smominru was initially detected in May 2017 and was also detected in January 2018. Last year, researchers at security firm, Proofpoint, confirmed that Smominru had been using a National Security Agency (NSA) exploit. This exploit, known as EternalBlue, infects computers with XMR mining malware.

Regarding the latest iteration of the malware, Carbon Black discovered the modifications when they found “unusual activity” across several endpoints. They found sophisticated, multi-stage malware that was sending detailed system metadata to a network of hijacked web servers.” Back in September 2018, the Monero community members released a blog post condemning all such XMR mining malware attacks:

“[We] condemn this malicious, non-consensual use of equipment to mine (XMR) … The Monero community does not want to sit idly by as victims struggle to understand the impact of mining and ransomware.”

Author

Rajarshi Mitra

Rajarshi Mitra

Independent Analyst

Rajarshi entered the blockchain space in 2016. He is a blockchain researcher who has worked for Blockgeeks and has done research work for several ICOs. He gets regularly invited to give talks on the blockchain technology and cryptocurrencies.

More from Rajarshi Mitra
Share:

Editor's Picks

Sonic Labs’ vertical integration fuels recovery in S token

Sonic, previously Fantom (FTM), is extending its recovery trade at $0.048 at the time of writing, after rebounding by over 12% the previous day. The recovery thesis’ strengths lie in the optimism surrounding Sonic Labs’ Wednesday announcement to shift to a vertically integrated model, aimed at boosting S token utility. 

Midnight Price Forecast: NIGHT warms up as Hoskinson reveals March mainnet release

Midnight edges higher by 2% at press time on Thursday, driven by its founder announcing the mainnet release by late March at the Consensus 2026 event. The technical outlook for Midnight highlights a potential bottom formation that could ignite the next bullish trend.

Cardano Price Forecast: ADA eyes short-term rebound as derivatives sentiment improves

Cardano (ADA) is trading at $0.257 at the time of writing on Thursday, after slipping more than 4% so far this week. Derivatives sentiment improves as ADA’s funding rates turn positive alongside rising long bets among traders.

Top Crypto Gainers: Pippin rally logs over 75% gains, Aster and Kaia push higher

Altcoins, such as Pippin (PIPPIN), Aster (ASTER) and Kaia (KAIA) continue to trade in the green, defying the broader market pullback as Bitcoin (BTC) dropped to below $68,000. PIPPIN continues to rally and ASTER and KAIA show short-term recovery with possibilities of a breakout rally.

Bitcoin Price Annual Forecast: BTC holds long-term bullish structure heading into 2026

Bitcoin (BTC) is wrapping up 2025 as one of its most eventful years, defined by unprecedented institutional participation, major regulatory developments, and extreme price volatility.

Bitcoin: The worst may be behind us

Bitcoin (BTC) price recovers slightly, trading at $65,000 at the time of writing on Friday, after reaching a low of $60,000 during the early Asian trading session. The Crypto King remained under pressure so far this week, posting three consecutive weeks of losses exceeding 30%.