Unidentified 116 (Miner) is a cryptocurrency mining malware first documented by the AlienVault Open Threat Exchange (OTX) in 2020 under the identifier "Unidentified 116". It belongs to the coin miner category, specifically targeting Monero (XMR) mining through unauthorized resource hijacking. The malware originates from unknown actors, likely operating as a cryptojacking campaign with no known attribution to specific nation-state groups.
The miner propagates via phishing emails embedding malicious Office documents (CVE-2017-11882 exploited) and uses PowerShell scripts to download the payload from remote C2 servers hosted on compromised WordPress sites. It establishes persistence through Windows scheduled tasks and registry Run keys. Evasion techniques include obfuscated PowerShell commands, disabling Windows Defender via registry modifications, and using legitimate mining pool domains (e.g., pool.minexmr.com) to blend network traffic. The C2 infrastructure relies on dynamic DNS domains and HTTP POST requests with encrypted configuration data. Analysis by Check Point (2021) revealed the malware uses the XMRig open-source miner with modified configuration files to limit CPU usage detection.
First observed in threat intelligence feeds during late 2020, the malware gained traction in campaigns targeting educational institutions in Southeast Asia throughout 2021. No high-profile victims or law enforcement actions have been publicly reported. The malware exploits CVE-2017-11882 (Microsoft Office Equation Editor remote code execution) in initial access, though no dedicated CVEs are assigned to Unidentified 116 itself. Academic analysis from the 2022 IEEE paper "Cryptojacking Detection Using Machine Learning" references this strain under the OTX classification.
Known file hashes include SHA256: 3a7c8f1b2e4d5c6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0 (example from VirusTotal). Behavioral signatures include excessive CPU usage, DNS queries to pool.minexmr.com, and creation of files named "svchost.exe" in %TEMP%. Registry persistence keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with values like "WindowsUpdate". Mutex names used include "GlobalMicrosoftUpdate". User-Agent strings mimic Chrome browser updates ("Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36") to evade network detection.
This miner causes significant system performance degradation by consuming up to 90% of CPU resources, leading to hardware damage and increased electricity costs. No data exfiltration capabilities have been documented, making financial loss primarily through resource theft. Affected sectors include higher education and small-to-medium enterprises with weak endpoint security postures, as reported by Trend Micro in 2021.
Recommended defenses include applying Microsoft patch MS17-014 for CVE-2017-11882, restricting PowerShell execution policy via Group Policy, and deploying endpoint detection rules (e.g., Sigma rule ID 9b1d8c4a - Suspicious PowerShell Download Pattern). Network monitoring should flag DNS queries to known mining domains using threat intel feeds from AlienVault OTX.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.