Share this article

New Crypto Mining Malware Seen to 'Evolve,' Say Researchers

Researchers at cybersecurity firm Check Point say a relatively new form of crypto mining malware, dubbed KingMiner, is “evolving.”

Updated Sep 13, 2021, 8:38 a.m. Published Nov 30, 2018, 3:00 p.m.
virus 3d

Researchers at Israel-based cybersecurity firm Check Point Software Technologies say that a relatively new form of crypto mining malware, dubbed KingMiner, is “evolving.”

In a research note on Thursday, the firm's Ido Solomon and Adi Ikan said that KingMiner, a monero mining malware that first appeared about six months ago, is changing through time to avoid detection – even replacing older versions of itself that it encounters on host machines.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters

The researchers said:

“The malware continuously adds new features and bypass methods to avoid emulation. Mainly, it manipulates the needed files and creates a dependency which is critical during emulation.”

As a result of these tactics, the malware is also being detected by security systems at "significantly" reduced rates.

The malware usually targets Microsoft servers (predominantly IIS\SQL) and while configured to harness 75 percent of the victim machine's CPU capacity for mining, it actually uses up the full 100 percent.

To preserve its secrecy, KingMiner is also seen to use a private mining pool to avoid detection, which also has its API switched off.

"We have not yet determined which domains are used, as this is also private. However, we can see that the attack is currently widely spread, from Mexico to India, Norway and Israel," the researchers said.

The continual changes allow the malware to be more successful, they continued, predicting that such evasion techniques will continue to evolve during 2019 and become more common across crypto-mining malware variants.

Virus illustration via Shutterstock

More For You

State of the Blockchain 2025

State of the Blockchain 16:9

L1 tokens broadly underperformed in 2025 despite a backdrop of regulatory and institutional wins. Explore the key trends defining ten major blockchains below.

What to know:

2025 was defined by a stark divergence: structural progress collided with stagnant price action. Institutional milestones were reached and TVL increased across most major ecosystems, yet the majority of large-cap Layer-1 tokens finished the year with negative or flat returns.

This report analyzes the structural decoupling between network usage and token performance. We examine 10 major blockchain ecosystems, exploring protocol versus application revenues, key ecosystem narratives, mechanics driving institutional adoption, and the trends to watch as we head into 2026.

More For You

Altcoins outpace bitcoin as precious metals' historic rally keeps macro focus sharp

Hands rest on the keyboard of a laptop showing trading graphs, data. (Kanchanara / Unsplash modified by CoinDesk)

Altcoins posted broader gains in quiet Sunday trading as bitcoin held a tight range near $88K and analysts weighed crypto against the surge in precious metals.

What to know:

  • XRP, dogecoin and solana outperformed bitcoin and ether over the past 24 hours in thin weekend trading.
  • Analysts said bitcoin remains range-bound between roughly $86,500 and $90,000.
  • Glassnode flagged spot price sitting near one on-chain mean while remaining well below short-term holders’ cost basis.