
Same XMRig Miner Build Resurfaces Under New Names Since 2019
Six files sharing one imphash and identical PE build metadata trace a single PyInstaller/UPX-wrapped XMRig miner distributed under Video, Photo, and AV-themed lures from June 2019 through June 2025. The cluster is unanimously flagged as a cryptominer by sandboxes, yet arrives labeled with an 'espionage' motivation and a 'Rampant Kitten' actor reference that the technical evidence doesn't support.
A single compiled Windows binary — identified by the import-table fingerprint imphash 91ae93ed3ff0d6f8a4f22d2edd30a58e — has been circulating since June 2019, and a fresh copy of the same build turned up again as recently as June 17, 2025. Six files share that imphash, an identical rich PE header hash (50dce46bb94bc57fb0152942a792d7e2), the same PE compile timestamp (2018-09-04) and the same entry point (31187).
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read