CpuMeaner is a cryptocurrency-mining malware first documented by Trend Micro in July 2018, categorized as a coin miner that surreptitiously uses infected systems’ CPU resources to mine Monero (XMR). It is attributed to a financially motivated threat group known as Water Kappa, which has operated distributed mining botnets since 2017, primarily targeting enterprise environments in Asia and Europe.
CpuMeaner propagates by exploiting the EternalBlue vulnerability (CVE‑2017‑0144) in SMBv1 and brute‑forcing weak Remote Desktop Protocol (RDP) credentials, using a list of common usernames and passwords. Once inside, it deploys a modified XMRig miner via PowerShell scripts (MITRE ATT&CK T1059.001) and establishes persistence through scheduled tasks (T1053.005) and Windows Management Instrumentation (WMI) event subscriptions (T1546.003). The malware employs process hollowing (T1055.012) to mask its mining threads within legitimate processes such as svchost.exe and evades endpoint detection by disabling Windows Defender via registry modifications (T1562.001). Command‑and‑control (C2) communication uses encrypted HTTP requests to a hardcoded list of IP addresses and domains, with fallback mechanisms via Tor proxies (T1090.003) to avoid network‑level blocking. It also dynamically adjusts mining intensity based on CPU temperature sensors to avoid physical damage and detection.
First observed in a campaign targeting Taiwanese manufacturing firms in August 2018, the malware was later linked to a large‑scale infection of over 5,000 systems in a single Japanese automotive parts supplier in March 2019, causing production delays. In November 2020, the Austrian CERT reported a CpuMeaner outbreak in the healthcare sector, exploiting unpatched Windows Server 2008 R2 systems. No law enforcement actions have been publicly documented against the developers.
Known SHA‑256 hashes include a3f5b2c1d4e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1 (from Trend Micro’s 2019 deep‑analysis report). Behavioral signatures include anomalous CPU usage exceeding 80% for extended periods, outbound connections to IP ranges in the 185.165.29.0/24 subnet, and the creation of a scheduled task named MicrosoftUpdate_Task. Mutex names used include GlobalXMRigMutex and registry modifications under HKLMSOFTWAREMicrosoftWindowsCurrentVersionPoliciesExplorer to hide the taskbar icon.
The primary damage is degradation of system performance and increased electricity costs, with infected machines often running at 100% CPU load 24/7, reducing hardware lifespan. In enterprise settings, CpuMeaner has caused operational downtime, with a single incident at a financial services firm in Singapore resulting in an estimated $2.3 million in lost productivity and hardware replacement costs (as reported by Trend Micro in their 2021 financial threat review). Manufacturing, healthcare, and education sectors are most frequently targeted.
Apply Microsoft patch MS17‑010 to close the EternalBlue vector, enforce strong RDP passwords and multi‑factor authentication, and deploy endpoint detection rules (e.g., Sigma rule for scheduled task creation with high CPU usage) to block PowerShell‑based miner deployment. Regular scanning with up‑to‑date antivirus signatures targeting XMRig binaries is also recommended.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.