Cryptomining Campaign Evades Detection by Avoiding Root Access on Linux Servers
Rapid Read

Cryptomining Campaign Evades Detection by Avoiding Root Access on Linux Servers

What's Happening? A cryptomining operation has been identified that deliberately avoids root access on compromised Linux servers to bypass security alerts. The campaign, discovered by Group-IB in May 2026, uses a modified XMRig miner. Attackers gain initial access through third-party relationships a
AI Generated
This may include content generated using AI tools. Glance teams are making active and commercially reasonable efforts to moderate all AI generated content. Glance moderation processes are improving however our processes are carried out on a best-effort basis and may not be exhaustive in nature. Glance encourage our users to consume the content judiciously and rely on their own research for accuracy of facts. Glance maintains that all AI generated content here is for entertainment purposes only.