Netskope Threat Labs

Malxmr

ATP Sandbox Adv. Heuristics

This generic detection identifies cryptocurrency miners based on the XMRig software that abuse the resources of infected systems to mine Monero.

First seen
March 2022
Last seen
October 2026
Alert Name
ByteCode-JAVA.Trojan.Malxmr
ByteCode-MSIL.Coinminer.Malxmr
Linux.Coinminer.Malxmr
Linux.Trojan.Malxmr
MacOS.Coinminer.Malxmr
Script-AutoIt.Coinminer.Malxmr
Script-BAT.Coinminer.Malxmr
Script-JS.Coinminer.Malxmr
Script-Shell.Coinminer.Malxmr
Win32.Coinminer.Malxmr