#randomx — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #randomx, aggregated by home.social.
-
How to Stay Protected
XMRig Malware Campaigns Target Businesses
Cybersecurity threats continue to evolve, and one of the most persistent threats facing businesses today involves cybercriminals abusing the popular XMRig mining software. While XMRig is a legitimate, open-source cryptocurrency miner used by many enthusiasts to mine Monero (XMR), attackers frequently modify or secretly install it on corporate computers to generate profits without the owner’s knowledge.
In this article, we’ll explain how XMRig is being misused in corporate environments, the risks to businesses, how these attacks work, and the best practices to prevent them.
What Is XMRig?
XMRig is a free and open-source CPU and GPU miner designed primarily for mining Monero (XMR). It is widely respected within the cryptocurrency community because it is efficient, actively maintained, and available for Windows, Linux, and macOS.
By itself, XMRig is not malware. However, cybercriminals often bundle modified versions of XMRig with malicious software or deploy it after compromising a computer.
Why Are Businesses Being Targeted?
Corporate environments provide an attractive opportunity for attackers because they often contain:
- High-performance desktop computers
- Powerful servers
- Multiple workstations
- Cloud infrastructure
- Continuous internet connectivity
Instead of mining cryptocurrency on their own hardware, attackers infect company devices and secretly use the organisation’s computing power.
The result is free cryptocurrency mining at the company’s expense.
How XMRig Malware Gets Installed
Most unauthorised XMRig installations begin after another security weakness has already been exploited.
Common infection methods include:
- Phishing emails containing malicious attachments
- Fake software downloads
- Exploitation of unpatched vulnerabilities
- Weak Remote Desktop Protocol (RDP) passwords
- Stolen administrator credentials
- Trojan malware that downloads additional payloads
Once attackers gain access, they silently install XMRig and configure it to connect to their own mining pools.
Warning Signs of an XMRig Infection
Many organisations discover mining malware only after performance problems become noticeable.
Common symptoms include:
- Constantly high CPU usage
- Increased electricity consumption
- Slow computers
- Loud cooling fans
- Servers running hotter than normal
- Unknown scheduled tasks
- Unexpected outbound network traffic
- Security software being disabled
Some attackers even configure XMRig to stop mining whenever a user opens Task Manager, making detection more difficult.
Business Impact
Although cryptojacking usually does not encrypt files like ransomware, it can still cause significant operational issues.
Potential consequences include:
Reduced Productivity
Employees experience slower computers, affecting daily work.
Higher Operating Costs
Mining consumes CPU resources and electricity around the clock.
Hardware Wear
Continuous high CPU usage can shorten the lifespan of processors, cooling systems, and power supplies.
Security Risks
An XMRig infection often indicates that attackers already have unauthorised access to the network, meaning sensitive business data may also be at risk.
How Organisations Can Protect Themselves
Preventing cryptojacking requires multiple layers of security.
Keep Systems Updated
Install security updates for Windows, Linux, browsers, and all business software as soon as practical.
Use Endpoint Protection
Modern antivirus and endpoint detection solutions can identify suspicious mining behaviour before it becomes widespread.
Enable Multi-Factor Authentication
Protect administrator accounts and remote access services with MFA wherever possible.
Monitor CPU Usage
Investigate unexplained spikes in processor utilisation, especially outside business hours.
Restrict Administrative Privileges
Limit local administrator permissions to reduce the impact of compromised accounts.
Educate Employees
Regular cybersecurity awareness training helps staff recognise phishing emails and other social engineering attacks.
Is XMRig Dangerous?
The software itself is completely legitimate.
The danger comes from unauthorised installation and misuse by attackers.
Many security vendors detect unauthorised XMRig deployments because they are commonly associated with cryptojacking campaigns rather than because the software itself is malicious.
Best Practices for IT Teams
Organisations should adopt a proactive security strategy by:
- Regularly auditing endpoints
- Monitoring unusual network connections
- Reviewing scheduled tasks and startup entries
- Enforcing least-privilege access
- Conducting vulnerability scans
- Backing up critical business data
- Implementing continuous security monitoring
Early detection significantly reduces the financial and operational impact of mining malware.
Final Thoughts
Cryptocurrency mining software like XMRig serves legitimate purposes for individuals and organisations that choose to mine digital assets. However, when cybercriminals secretly deploy XMRig on corporate systems, it becomes part of a cryptojacking attack that wastes resources, increases costs, and may signal a broader security compromise.
Businesses should combine strong cybersecurity practices, employee awareness, regular patching, and continuous monitoring to minimise the risk of unauthorised mining software running within their networks.
By understanding how these attacks operate and responding quickly to suspicious activity, organisations can better protect their infrastructure, maintain productivity, and reduce the likelihood of future compromises.
Frequently Asked Questions
Is XMRig malware?
No. XMRig is legitimate open-source cryptocurrency mining software. It only becomes part of malicious activity when attackers install it without permission.
What cryptocurrency does XMRig mine?
It is primarily designed to mine Monero (XMR) using the RandomX algorithm.
Can antivirus detect XMRig?
Many security products detect unauthorised XMRig installations because they are commonly used in cryptojacking attacks.
How can I tell if my computer is mining cryptocurrency?
Persistent high CPU usage, overheating, increased fan noise, slow performance, and unexplained network connections can all indicate possible cryptojacking.
#Technology #ai #businessSecurity #corporateSecurity #cpuMining #cryptoMalware #cryptocurrencyMining #cryptojacking #cyberSecurity #cyberThreats #cyberSecurity #cybersecurity #dataProtection #endpointSecurity #enterpriseCybersecurity #ITSecurity #LinuxSecurity #malwareDetection #malwareProtection #miningMalware #Monero #MoneroMiner #MoneroMining #networkSecurity #phishingAttacks #RandomX #ransomware #security #securityAwareness #serverSecurity #WindowsSecurity #XMRig #XMRigMalware #XMRigMiner -
How to Stay Protected
XMRig Malware Campaigns Target Businesses
Cybersecurity threats continue to evolve, and one of the most persistent threats facing businesses today involves cybercriminals abusing the popular XMRig mining software. While XMRig is a legitimate, open-source cryptocurrency miner used by many enthusiasts to mine Monero (XMR), attackers frequently modify or secretly install it on corporate computers to generate profits without the owner’s knowledge.
In this article, we’ll explain how XMRig is being misused in corporate environments, the risks to businesses, how these attacks work, and the best practices to prevent them.
What Is XMRig?
XMRig is a free and open-source CPU and GPU miner designed primarily for mining Monero (XMR). It is widely respected within the cryptocurrency community because it is efficient, actively maintained, and available for Windows, Linux, and macOS.
By itself, XMRig is not malware. However, cybercriminals often bundle modified versions of XMRig with malicious software or deploy it after compromising a computer.
Why Are Businesses Being Targeted?
Corporate environments provide an attractive opportunity for attackers because they often contain:
- High-performance desktop computers
- Powerful servers
- Multiple workstations
- Cloud infrastructure
- Continuous internet connectivity
Instead of mining cryptocurrency on their own hardware, attackers infect company devices and secretly use the organisation’s computing power.
The result is free cryptocurrency mining at the company’s expense.
How XMRig Malware Gets Installed
Most unauthorised XMRig installations begin after another security weakness has already been exploited.
Common infection methods include:
- Phishing emails containing malicious attachments
- Fake software downloads
- Exploitation of unpatched vulnerabilities
- Weak Remote Desktop Protocol (RDP) passwords
- Stolen administrator credentials
- Trojan malware that downloads additional payloads
Once attackers gain access, they silently install XMRig and configure it to connect to their own mining pools.
Warning Signs of an XMRig Infection
Many organisations discover mining malware only after performance problems become noticeable.
Common symptoms include:
- Constantly high CPU usage
- Increased electricity consumption
- Slow computers
- Loud cooling fans
- Servers running hotter than normal
- Unknown scheduled tasks
- Unexpected outbound network traffic
- Security software being disabled
Some attackers even configure XMRig to stop mining whenever a user opens Task Manager, making detection more difficult.
Business Impact
Although cryptojacking usually does not encrypt files like ransomware, it can still cause significant operational issues.
Potential consequences include:
Reduced Productivity
Employees experience slower computers, affecting daily work.
Higher Operating Costs
Mining consumes CPU resources and electricity around the clock.
Hardware Wear
Continuous high CPU usage can shorten the lifespan of processors, cooling systems, and power supplies.
Security Risks
An XMRig infection often indicates that attackers already have unauthorised access to the network, meaning sensitive business data may also be at risk.
How Organisations Can Protect Themselves
Preventing cryptojacking requires multiple layers of security.
Keep Systems Updated
Install security updates for Windows, Linux, browsers, and all business software as soon as practical.
Use Endpoint Protection
Modern antivirus and endpoint detection solutions can identify suspicious mining behaviour before it becomes widespread.
Enable Multi-Factor Authentication
Protect administrator accounts and remote access services with MFA wherever possible.
Monitor CPU Usage
Investigate unexplained spikes in processor utilisation, especially outside business hours.
Restrict Administrative Privileges
Limit local administrator permissions to reduce the impact of compromised accounts.
Educate Employees
Regular cybersecurity awareness training helps staff recognise phishing emails and other social engineering attacks.
Is XMRig Dangerous?
The software itself is completely legitimate.
The danger comes from unauthorised installation and misuse by attackers.
Many security vendors detect unauthorised XMRig deployments because they are commonly associated with cryptojacking campaigns rather than because the software itself is malicious.
Best Practices for IT Teams
Organisations should adopt a proactive security strategy by:
- Regularly auditing endpoints
- Monitoring unusual network connections
- Reviewing scheduled tasks and startup entries
- Enforcing least-privilege access
- Conducting vulnerability scans
- Backing up critical business data
- Implementing continuous security monitoring
Early detection significantly reduces the financial and operational impact of mining malware.
Final Thoughts
Cryptocurrency mining software like XMRig serves legitimate purposes for individuals and organisations that choose to mine digital assets. However, when cybercriminals secretly deploy XMRig on corporate systems, it becomes part of a cryptojacking attack that wastes resources, increases costs, and may signal a broader security compromise.
Businesses should combine strong cybersecurity practices, employee awareness, regular patching, and continuous monitoring to minimise the risk of unauthorised mining software running within their networks.
By understanding how these attacks operate and responding quickly to suspicious activity, organisations can better protect their infrastructure, maintain productivity, and reduce the likelihood of future compromises.
Frequently Asked Questions
Is XMRig malware?
No. XMRig is legitimate open-source cryptocurrency mining software. It only becomes part of malicious activity when attackers install it without permission.
What cryptocurrency does XMRig mine?
It is primarily designed to mine Monero (XMR) using the RandomX algorithm.
Can antivirus detect XMRig?
Many security products detect unauthorised XMRig installations because they are commonly used in cryptojacking attacks.
How can I tell if my computer is mining cryptocurrency?
Persistent high CPU usage, overheating, increased fan noise, slow performance, and unexplained network connections can all indicate possible cryptojacking.
#Technology #ai #businessSecurity #corporateSecurity #cpuMining #cryptoMalware #cryptocurrencyMining #cryptojacking #cyberSecurity #cyberThreats #cyberSecurity #cybersecurity #dataProtection #endpointSecurity #enterpriseCybersecurity #ITSecurity #LinuxSecurity #malwareDetection #malwareProtection #miningMalware #Monero #MoneroMiner #MoneroMining #networkSecurity #phishingAttacks #RandomX #ransomware #security #securityAwareness #serverSecurity #WindowsSecurity #XMRig #XMRigMalware #XMRigMiner -
In other news, Bitmain has abandoned their previously announced (and presold!) #Monero #RandomX mining "ASIC". Probably its efficiency just isn't competitive. https://pcpraha.cz/en/Other/antminer-x9-canceled-bitmain-withdraws-model-from-market-before-launch-what-does-this-mean-for-monero-mining/
-
In other news, Bitmain has abandoned their previously announced (and presold!) #Monero #RandomX mining "ASIC". Probably its efficiency just isn't competitive. https://pcpraha.cz/en/Other/antminer-x9-canceled-bitmain-withdraws-model-from-market-before-launch-what-does-this-mean-for-monero-mining/
-
Funny what you find on #yggdrasil network.
#ALFIS #blockchain #ygg #Blakeout #RandomX #BoykisserGroup #boykisser
-
Funny what you find on #yggdrasil network.
#ALFIS #blockchain #ygg #Blakeout #RandomX #BoykisserGroup #boykisser
-
Brace yourselves, tech-savvy keyboard warriors! 🌪️ Dive into the exhilarating world of Monero's #RandomX, where #mining is basically a chaotic #CPU day job! 😂 Forget those efficient chips, it's time to watch CPUs sweat like they're running a marathon at a tech circus! 🤡🎪
https://blog.alcazarsec.com/tech/posts/how-moneros-proof-of-work-works #Monero #TechCircus #ChaoticMining #KeyboardWarriors #HackerNews #ngated -
Brace yourselves, tech-savvy keyboard warriors! 🌪️ Dive into the exhilarating world of Monero's #RandomX, where #mining is basically a chaotic #CPU day job! 😂 Forget those efficient chips, it's time to watch CPUs sweat like they're running a marathon at a tech circus! 🤡🎪
https://blog.alcazarsec.com/tech/posts/how-moneros-proof-of-work-works #Monero #TechCircus #ChaoticMining #KeyboardWarriors #HackerNews #ngated -
RandomX version 2.0 released https://github.com/tevador/RandomX/releases/tag/v2.0
Changes:
Program size increased from 256 to 384
CFROUND tweaked to change the rounding 16 times less often
Group F and E register mix is done using 16 AES operations (the extra 262144 AES ops come from this change)
Dataset prefetch is 2 iterations ahead instead of 1v1 hash: 4194304 VM instructions + 262144 AES = 4456448 total ops
v2 hash: 6291456 VM instructions + 524288 AES = 6815744 total ops (+52.9%) -
RandomX version 2.0 released https://github.com/tevador/RandomX/releases/tag/v2.0
Changes:
Program size increased from 256 to 384
CFROUND tweaked to change the rounding 16 times less often
Group F and E register mix is done using 16 AES operations (the extra 262144 AES ops come from this change)
Dataset prefetch is 2 iterations ahead instead of 1v1 hash: 4194304 VM instructions + 262144 AES = 4456448 total ops
v2 hash: 6291456 VM instructions + 524288 AES = 6815744 total ops (+52.9%) -
RandomX + P2Pool = truly decentralized mining
Monero's RandomX is optimized for CPUs — no ASICs, no GPU farms. P2Pool handles 15%+ of hashrate, decentralized, no pool operator to censor. Every CPU contributes.
This is what Satoshi envisioned: one-CPU-one-vote. Combined with privacy-by-default, Monero is the closest thing to the original Bitcoin whitepaper vision.
#Monero #XMR #Mining #P2Pool #RandomX #Decentralization #Privacy
-
RandomX + P2Pool = truly decentralized mining
Monero's RandomX is optimized for CPUs — no ASICs, no GPU farms. P2Pool handles 15%+ of hashrate, decentralized, no pool operator to censor. Every CPU contributes.
This is what Satoshi envisioned: one-CPU-one-vote. Combined with privacy-by-default, Monero is the closest thing to the original Bitcoin whitepaper vision.
#Monero #XMR #Mining #P2Pool #RandomX #Decentralization #Privacy
-
Looks like Arweave is adopting #LMDB now? https://github.com/permaweb/HyperBEAM/pull/309/commits/dde0a79d52643fe043b40adfa81e0c7290a446a3
It's amusing to me to see them adopting this code now, since they were the first project to adopt #RandomX. Early to adopt my recent work, late to adopt my early work. Also interesting to see that they use #Erlang - I first tried to develop an erlang wrapper for LMDB years ago to use in #riak, but all of that was abandoned.
-
Looks like Arweave is adopting #LMDB now? https://github.com/permaweb/HyperBEAM/pull/309/commits/dde0a79d52643fe043b40adfa81e0c7290a446a3
It's amusing to me to see them adopting this code now, since they were the first project to adopt #RandomX. Early to adopt my recent work, late to adopt my early work. Also interesting to see that they use #Erlang - I first tried to develop an erlang wrapper for LMDB years ago to use in #riak, but all of that was abandoned.
-
We recently celebrated the 5 year anniversary of the #RandomX ASIC-proof Proof-of-Work algorithm in production. https://old.reddit.com/r/Monero/comments/1h6e4nk/randomx_5_year_anniversary/
That writeup also includes links to history from the 2yr and 4yr anniversaries, if you aren't familiar with it. "They said it couldn't be done" but "they" were wrong. Bitcoin devs, Eth devs, etc., none of them could achieve this. But we did.
#Monero still the only true crypto currency guaranteeing privacy and egalitarian access for all.
-
We recently celebrated the 5 year anniversary of the #RandomX ASIC-proof Proof-of-Work algorithm in production. https://old.reddit.com/r/Monero/comments/1h6e4nk/randomx_5_year_anniversary/
That writeup also includes links to history from the 2yr and 4yr anniversaries, if you aren't familiar with it. "They said it couldn't be done" but "they" were wrong. Bitcoin devs, Eth devs, etc., none of them could achieve this. But we did.
#Monero still the only true crypto currency guaranteeing privacy and egalitarian access for all.
-
I didn't submit a talk to #Fosdem this year but will probably be attending. Ping me if you're interested in chatting about #LDAP, #OpenLDAP, #LMDB, #SymasCorp, #Monero, #RandomX, or whatever else comes to mind. #fosdem2024
-
I didn't submit a talk to #Fosdem this year but will probably be attending. Ping me if you're interested in chatting about #LDAP, #OpenLDAP, #LMDB, #SymasCorp, #Monero, #RandomX, or whatever else comes to mind. #fosdem2024
-
After spending a fortune to develop an unprofitable #RandomX miner, Bitmain is running out of money. You're welcome. https://mastodon.social/@web3isgreat@indieweb.social/111212632335059771
-
After spending a fortune to develop an unprofitable #RandomX miner, Bitmain is running out of money. You're welcome. https://mastodon.social/@web3isgreat@indieweb.social/111212632335059771
-
So, about 4 years after deployment, we have confirmation that Bitmain, the foremost mining ASIC producer in the world, couldn't produce a #RandomX mining ASIC. As expected, the best they could come up with was slapping a bunch of RISC-V CPUs in a box and calling it a "professional miner" - but notably, not an "asic miner". https://mastodon.social/@hyc/110976439561297760
The Sophon SG2042 they're based on is a big step forward for RISC-V, but still far behind AMD and Intel. All just as we predicted 5 years ago.
-
So, about 4 years after deployment, we have confirmation that Bitmain, the foremost mining ASIC producer in the world, couldn't produce a #RandomX mining ASIC. As expected, the best they could come up with was slapping a bunch of RISC-V CPUs in a box and calling it a "professional miner" - but notably, not an "asic miner". https://mastodon.social/@hyc/110976439561297760
The Sophon SG2042 they're based on is a big step forward for RISC-V, but still far behind AMD and Intel. All just as we predicted 5 years ago.
-
The Frontier supercomputer with 9408 AMD Epyc 7A53 64core CPUs at 2GHz can probably hit around 510MH/s on #RandomX (guessing, based on existing benchmarks of 32core Epyc 7452 at 2.35GHz). Its peak power consumption is 40MW but that includes its GPU accelerators, so total CPU-only would be half that or less.
We'll never know for sure because Frontier runs at 90% utilization 24/7 doing scientific number crunching jobs.
https://mastodon.social/@HPC_Guru/111110221954847718
https://xmrig.com/benchmark?cpu=AMD+EPYC+7452+32-Core+Processor
-
The Frontier supercomputer with 9408 AMD Epyc 7A53 64core CPUs at 2GHz can probably hit around 510MH/s on #RandomX (guessing, based on existing benchmarks of 32core Epyc 7452 at 2.35GHz). Its peak power consumption is 40MW but that includes its GPU accelerators, so total CPU-only would be half that or less.
We'll never know for sure because Frontier runs at 90% utilization 24/7 doing scientific number crunching jobs.
https://mastodon.social/@HPC_Guru/111110221954847718
https://xmrig.com/benchmark?cpu=AMD+EPYC+7452+32-Core+Processor
-
Just did an interview with @MoneroTalk
https://m.youtube.com/watch?v=T9BFnn2-TDM
discussing recent rumors of a new Bitmain "ASIC" for mining #Monero #RandomX -
Just did an interview with @MoneroTalk
https://m.youtube.com/watch?v=T9BFnn2-TDM
discussing recent rumors of a new Bitmain "ASIC" for mining #Monero #RandomX -
Thinking about designing an ASIC for #RandomX? Good luck with that.
-
Thinking about designing an ASIC for #RandomX? Good luck with that.
-
Just did an interview a couple weeks ago about how we designed #Monero 's mining #PoW algorithm #RandomX among other topics. The video went online yesterday: https://m.youtube.com/watch?v=abEek1mnchQ
-
Just did an interview a couple weeks ago about how we designed #Monero 's mining #PoW algorithm #RandomX among other topics. The video went online yesterday: https://m.youtube.com/watch?v=abEek1mnchQ
-
New toy - mining #Monero on my car stereo #RandomX https://mobile.twitter.com/hyc_symas/status/1600857111793057792
-
New toy - mining #Monero on my car stereo #RandomX https://mobile.twitter.com/hyc_symas/status/1600857111793057792
-
Today is the 3-year anniversary of the #RandomX Proof of Work algorithm on the #Monero mainnet. A completely CPU-bound PoW that is un-optimizable and infeasible to implement in a single-purpose ASIC.
Skeptics said it was impossible to design such an algorithm, and that an ASIC that outclassed CPUs would appear within 3 months. SChernyk, tevador, and I proved them wrong. 3 years later, no ASICs in sight. https://bitinfocharts.com/comparison/hashrate-price-xmr.html#3y
-
Today is the 3-year anniversary of the #RandomX Proof of Work algorithm on the #Monero mainnet. A completely CPU-bound PoW that is un-optimizable and infeasible to implement in a single-purpose ASIC.
Skeptics said it was impossible to design such an algorithm, and that an ASIC that outclassed CPUs would appear within 3 months. SChernyk, tevador, and I proved them wrong. 3 years later, no ASICs in sight. https://bitinfocharts.com/comparison/hashrate-price-xmr.html#3y
-