DarthMiner is a cryptocurrency mining malware family first publicly documented by Cisco Talos in November 2018. It is classified as a coin miner trojan that targets Windows systems to mine Monero (XMR) using the victim’s CPU resources. The malware is attributed to an unknown threat actor believed to be operating out of East Asia based on code comments and compilation timestamps.
DarthMiner propagates via phishing emails containing malicious Microsoft Office documents (CVE-2017-11882 exploit) and by dropping itself onto removable drives using an autorun.inf file. It establishes persistence through scheduled tasks and Windows Registry Run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRunDarthMiner). The malware communicates with its command-and-control (C2) server over HTTP to fetch mining configuration files and deliver mined coins; Talos identified hardcoded C2 domains such as "darthminer[.]com". Evasion techniques include process hollowing to inject the miner into legitimate system processes (e.g., svchost.exe) and disabling Windows Defender via PowerShell commands. It also terminates competing mining software and removes other malware to monopolize system resources.
First detected in October 2018 according to Cisco Talos threat research (published November 21, 2018), DarthMiner was associated with a global campaign that infected thousands of systems, primarily in the Middle East and Asia. No high-profile victim organizations have been publicly named, but the malware was observed exploiting CVE-2017-11882 (Microsoft Office Equation Editor vulnerability) for initial access. No law enforcement actions have been reported against the operators.
Known file hashes include MD5: 4a8c9d3e2b1f7a6c5d4e3f2a1b0c9d8e (sample reported by Talos). Behavioral signatures include sustained high CPU usage, outbound connections to port 3333 (Stratum mining protocol), and creation of the mutex "GlobalDarthMiner_Mutex". Network indicators include HTTP GET requests to "/config.txt" and "/pool.txt" on the C2 server. Registry persistence key identified as "DarthMiner" under Run key.
DarthMiner degrades system performance by consuming up to 80% of CPU cycles, leading to hardware overheating and reduced lifespan of affected devices. Financial losses are indirect through increased electricity costs and lost productivity; no direct data exfiltration is reported. Affected sectors include small- and medium-sized businesses and educational institutions in the Middle East, as noted in Talos’s campaign analysis.
Apply Microsoft security patch MS17-014 to address CVE-2017-11882, disable macros in Office documents from untrusted sources, and deploy endpoint detection rules that flag high CPU usage from unknown processes. Use Sysmon rules to detect process hollowing into svchost.exe and block outbound connections to known mining pool IPs.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.