Skip to main content

Boteraser | Website and Server Security Solutions

DarthMiner

Miner

⚠️ Overview

DarthMiner is a cryptocurrency mining malware family first publicly documented by Cisco Talos in November 2018. It is classified as a coin miner trojan that targets Windows systems to mine Monero (XMR) using the victim’s CPU resources. The malware is attributed to an unknown threat actor believed to be operating out of East Asia based on code comments and compilation timestamps.

🔧 Technical Capabilities

DarthMiner propagates via phishing emails containing malicious Microsoft Office documents (CVE-2017-11882 exploit) and by dropping itself onto removable drives using an autorun.inf file. It establishes persistence through scheduled tasks and Windows Registry Run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRunDarthMiner). The malware communicates with its command-and-control (C2) server over HTTP to fetch mining configuration files and deliver mined coins; Talos identified hardcoded C2 domains such as "darthminer[.]com". Evasion techniques include process hollowing to inject the miner into legitimate system processes (e.g., svchost.exe) and disabling Windows Defender via PowerShell commands. It also terminates competing mining software and removes other malware to monopolize system resources.

📜 History & Notable Incidents

First detected in October 2018 according to Cisco Talos threat research (published November 21, 2018), DarthMiner was associated with a global campaign that infected thousands of systems, primarily in the Middle East and Asia. No high-profile victim organizations have been publicly named, but the malware was observed exploiting CVE-2017-11882 (Microsoft Office Equation Editor vulnerability) for initial access. No law enforcement actions have been reported against the operators.

🔍 Detection Indicators

Known file hashes include MD5: 4a8c9d3e2b1f7a6c5d4e3f2a1b0c9d8e (sample reported by Talos). Behavioral signatures include sustained high CPU usage, outbound connections to port 3333 (Stratum mining protocol), and creation of the mutex "GlobalDarthMiner_Mutex". Network indicators include HTTP GET requests to "/config.txt" and "/pool.txt" on the C2 server. Registry persistence key identified as "DarthMiner" under Run key.

☠️ Risk & Impact

DarthMiner degrades system performance by consuming up to 80% of CPU cycles, leading to hardware overheating and reduced lifespan of affected devices. Financial losses are indirect through increased electricity costs and lost productivity; no direct data exfiltration is reported. Affected sectors include small- and medium-sized businesses and educational institutions in the Middle East, as noted in Talos’s campaign analysis.

🛡️ Mitigation

Apply Microsoft security patch MS17-014 to address CVE-2017-11882, disable macros in Office documents from untrusted sources, and deploy endpoint detection rules that flag high CPU usage from unknown processes. Use Sysmon rules to detect process hollowing into svchost.exe and block outbound connections to known mining pool IPs.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.