Skip to content

Malware

Kingminer

According to Sophis, the botnet has been active since 2018, initially, the botmasters operated DDoS tools and backdoors, but later moved on to cryptocurrency miners.

Kingminer is a Windows malware family.

Background

Per Sophos, the botnet has run since 2018; its operators started out with DDoS tools and backdoors before shifting to cryptocurrency miners. They rely on a DGA to rotate their hosting domains automatically on a weekly basis.


Source: Malpedia (Fraunhofer FKIE).