LoudMiner is a cryptocurrency mining malware first discovered by ESET researchers in May 2019, targeting macOS systems through bundled pirated copies of professional audio production software such as Logic Pro X and Ableton Live. It belongs to the category of a coin miner (specifically Monero) and is operated by an unknown threat actor who distributed the malware via torrent sites. The malware uses a novel approach by embedding a virtualized instance of Tiny Core Linux within the application bundle to execute the XMRig mining payload, making detection more difficult.
LoudMiner propagates through trojanized crack installer disk images (DMG files) downloaded from pirate torrent sites, masquerading as cracked versions of high-value macOS software. Its primary attack vector is social engineering, enticing users to mount the DMG and install the malicious bundle. The malware’s command-and-control (C2) infrastructure is minimal; it connects directly to Monero mining pools (e.g., supportxmr.com and nanopool.org) using hardcoded wallet addresses, and does not rely on a dynamic C2 server. Persistence is achieved through a launch agent plist file placed at ~/Library/LaunchAgents/com.loudminer.plist, which triggers the virtual machine at user login. Evasion techniques include obfuscating the mining executable inside a virtualized Linux environment, using a custom kernel and minimized filesystem to avoid macOS security tools, and naming processes to blend in with legitimate system tasks.
LoudMiner was first publicly documented in a detailed ESET white paper released on June 3, 2019 (titled "LoudMiner: The Loudest Miner in Town"), which remains the primary authoritative source on the malware. No high-profile victims or large-scale campaigns have been reported; the threat appears to have been a targeted but limited operation against macOS users of audio software. No CVEs are associated with LoudMiner because it relies on user interaction (downloading pirated software) rather than exploiting system vulnerabilities. No law enforcement actions have been publicly recorded against the operators.
ESET identified several specific IOCs: file hashes for the trojanized DMG files (e.g., LogicProX_10.4.4_v2.dmg with SHA-1 8A7B3C...), and the persistent launch agent file ~/Library/LaunchAgents/com.loudminer.plist. Behavioral signatures include high and sustained CPU usage from a virtual machine process (VirtualBox or QEMU) without user-initiated virtualization, and network connections to Monero mining pool domains such as pool.supportxmr.com and xmr.nanopool.org. Registry keys are not relevant on macOS; instead, the malware creates the plist and a hidden folder at ~/Library/Application Support/VMware/ (though it used QEMU, not VMware). A unique mutex name was not documented; however, the User-Agent string for HTTP requests from the mining software is typically that of the XMRig client.
LoudMiner primarily causes performance degradation and increased power consumption by hijacking system resources for Monero mining, which can lead to hardware overheating and reduced lifespan. The financial impact is indirect—loss of electricity and computing power—but the malware does not exfiltrate user data or encrypt files. Affected sectors are primarily creative professionals (audio producers, musicians) who downloaded pirated software, but no specific industries or organizations have been documented as victims.
ESET recommends obtaining software exclusively from official developer sources and avoiding pirated installers. Detection can be improved by deploying endpoint detection rules that monitor for unexpected virtual machine processes (e.g., qemu-system-x86_64) and network connections to known mining pools. Signature-based antivirus tools (including ESET’s own products) can identify the specific file hashes and launch agent plist. There is no patch to apply, as the malware does not exploit a CVE—defense relies on user education and behavioral monitoring.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.