Skip to content
tag — xmrig

grep -rl "xmrig" ./articles

#xmrig

2 articles

The attribution came from commit emails across 84 GitHub accounts

2026-09-09Security

The DFIR Report traced a decade-old Bing poisoning operation — fake activation portals, tech support scams, a custom bot and a Monero miner — to two named companies in Rajasthan, using email addresses left in GitHub commit history. That is a far stronger evidentiary chain than most attribution, and it is worth saying so.

The rogue ScreenConnect clients infect the hosts that connect to them

2026-09-08Security

Huntress found ScreenConnect clients that write a four-stage VBScript chain onto machines as they connect, profile each host, and then request a different payload depending on how much RAM it has and which EDR is installed. There is no code execution vulnerability to patch — it abuses file transfer, and ConnectWise says the fix is to turn the permission off.