{
  "family": "coins",
  "sample_count": 359,
  "category": "cryptominer",
  "description": "There is no single, specific malware family universally referred to as \"coins.\" Instead, the term is frequently used by security vendors as a descriptor for entire categories of malicious software that focus on cryptocurrency. This most commonly refers to \"Coinminers\" (or cryptojackers) that hijack a victim's computer resources (CPU, RAM, or GPU) to mine cryptocurrencies like Monero without consent. It may also refer to Cryptocurrency Stealers, which are designed to locate and steal existing crypto assets by targeting wallet.dat files, hijacking clipboard contents to replace wallet addresses during transactions, or logging keystrokes to steal seed phrases.",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [],
  "enrichment_level": "curated_sourced",
  "faq": [
    {
      "@type": "Question",
      "name": "What does the 'coins' malware label mean?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "It is a generic category label used to describe malware that either steals existing cryptocurrency from wallets, or hijacks a computer's resources to mine new cryptocurrency for the attacker."
      }
    },
    {
      "@type": "Question",
      "name": "How does cryptojacking affect my computer?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Cryptominers often run silently in the background, significantly slowing down the victim's system, causing high CPU/GPU temperatures, and increasing electricity consumption."
      }
    },
    {
      "@type": "Question",
      "name": "How do cryptocurrency stealers work?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "They may search your hard drive for wallet files, monitor your clipboard to swap out legitimate wallet addresses with the attacker's address when you copy/paste, or log your keystrokes to steal passwords."
      }
    }
  ],
  "faq_count": 3,
  "mitre_attack": [],
  "cisa_advisory": null,
  "last_updated": "2026-06-09",
  "target_industries": [
    "Cloud Infrastructure",
    "Consumers"
  ],
  "motivation": "Financial Extortion",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}