Coinloader
Overview
Executive Summary
Coinloader is a specialized Trojan Downloader engineered with a singular, primary objective: to silently infect a system and subsequently download, install, and execute unauthorized cryptocurrency mining software (Cryptojacking). The malware hijacks the victim's CPU and GPU processing power to generate digital currency (typically Monero) for the threat actors.Infection Vector and Technical Capabilities
Coinloader is widely distributed via "fileless" attacks (such as exploiting vulnerabilities in unpatched web servers or databases like Redis/MSSQL), malicious email attachments, or hidden within pirated software and game torrents. Once executed on a host, Coinloader operates with a focus on resource hijacking:- Miner Deployment: The downloader reaches out to attacker-controlled infrastructure (often utilizing paste sites like Pastebin or compromised GitHub repositories) to download an open-source or custom-built mining application (e.g., XMRig).
- Stealth and Evasion: To prevent the user from noticing the massive spike in CPU usage, the loader often injects the miner into a legitimate Windows process (`svchost.exe`, `notepad.exe`). Advanced variants will actively monitor the Task Manager; if the user opens the Task Manager, the miner temporarily suspends its activity to hide the CPU spike.
- Defense Evasion: Coinloader frequently utilizes PowerShell scripts to modify Windows Defender settings, adding exclusions for its own directories to prevent the miner from being quarantined.
Threat Assessment
While Coinloader does not typically steal data or encrypt files like ransomware, it causes massive disruption. The constant 100% CPU/GPU utilization renders the workstation or server practically unusable, causes severe physical overheating (potentially damaging hardware), and significantly inflates corporate electricity and cloud computing costs.Incident Response and Remediation
- Network Isolation and Process Termination: Identify the process consuming massive CPU resources (often a legitimate-sounding process name running from an unusual directory like `%AppData%`). Terminate the process and isolate the machine to halt mining and prevent re-infection.
- Hunting for Persistence: Coinloader relies heavily on Scheduled Tasks and WMI (Windows Management Instrumentation) event subscriptions for persistence. Thoroughly audit these areas using PowerShell or EDR tools.
- Review AV Exclusions: Carefully review the local Antivirus/Windows Defender settings. The malware likely added folder or process exclusions that must be manually removed before a clean scan can be performed.
Known aliases
Threat reports may refer to this family under multiple names:
MITRE ATT&CK Techniques
This family has been observed using the following ATT&CK techniques: T1105 T1496 T1562.001 T1055
Tactical Mitigations
Based on the techniques used by this family, consider the following defensive strategies:
- T1105: Implement network intrusion detection systems (NIDS) and host-based firewalls to block unauthorized inbound or outbound file transfers.
Generated Detections (Boilerplate)
These YARA and Sigma rules are auto-generated based on the family name and aliases. They must be heavily tuned before deployment in a production environment.
YARA Rule
rule MALWARE_WIN_COINLOADER {
meta:
description = "Detects Coinloader (ransomware)"
author = "SystemHelpdesk Boilerplate Generator"
date = "2026-07-06"
strings:
$s1 = "coinloader" ascii wide nocase
$s2 = "trojan.downloader.coinminer" ascii wide nocase
$s3 = "riskware.coinloader" ascii wide nocase
$s4 = "coinminer" ascii wide nocase
condition:
uint16(0) == 0x5a4d and any of them
}Sigma Rule
title: Suspicious Coinloader Activity
id: 569aa7156b54a601289e17dc8a6b70f9
status: experimental
description: Detects generic indicators of the coinloader malware family.
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
CommandLine|contains:
- "*coinloader*"
- "*trojan.downloader.coinminer*"
- "*riskware.coinloader*"
- "*coinminer*"
condition: selection
level: mediumReferences & External Analysis
- Search "coinloader" on VirusTotal (External Analysis)
Frequently Asked Questions
How do I remove the Coinloader Ransomware from Windows?
Manual removal of Coinloader is highly discouraged as it may leave persistence mechanisms intact. We recommend disconnecting the device from the internet and utilizing a professional incident response service or enterprise-grade EDR software to conduct a full forensic sweep.
Is Coinloader a virus or a Ransomware?
Coinloader is classified as a Ransomware. Unlike traditional viruses that infect files, modern malware like Coinloader typically operates as a standalone payload designed to compromise systems, steal data, or deploy secondary stage implants.
What are the main symptoms of a Coinloader infection?
Symptoms of Coinloader can include unexpected system slowness, unauthorized outbound network traffic to unknown IP addresses, disabled security software, and suspicious background processes running from AppData or Temp directories.
Related Families (Category: ransomware)
Explore other malware families in the same category:
Protect Your Network Against Ransomwares
Want to prevent Coinloader and similar threats from compromising your organization? Read our comprehensive defensive guide: Ransomware Protection Guide.
Machine-readable
Get this profile as JSON: https://jordan123234-malware-families-explorer.static.hf.space/api/coinloader.json
Ecosystem & Interactive Environments
This profile is part of the Malware Families Catalog, a public dataset of 2,899 malware families. The catalog is also published across our ecosystem: Hugging Face, Kaggle, Zenodo, Replit, StackBlitz, CodeSandbox, and CodePen.