Blog · Threat intel · 2026-10-07 · 9 min

One server, three crypto crimes: wallet scanning, cryptojacking and pool brute-forcing

Not every exposed attacker server is subtle. On 23.252.123.134, a host at WebNX, Inc., an open directory laid out an entire Chinese-language cryptocurrency-theft operation, three separate money-making rackets wired to one control server.

Wallet scan
key-space engine
Cryptojack
GPU miner fleet
Brute-force
pool accounts
CN
operator language

Key findings

  • Three rackets, one control server. Wallet-key scanning, cryptojacking and mining-pool brute-forcing all stage payloads from, and report hits to, the same host (ports 8000/18095 for staging, 8899 for callbacks).
  • Stolen compute. The wallet scanner runs "inside hijacked YARN containers", Hadoop/YARN clusters are big, exposed and rarely watched, a long-standing cryptojacking target.
  • Textbook covert miner. A GPU-aware installer hides in /tmp/.scXXXX, exposes xmrig-style local APIs and persists via two crontab entries.
  • Theft layered on theft. Distributed workers brute-force a mining-pool platform's accounts to redirect other miners' payouts.

Architecture

C2 / collector23.252.123.134 :8899Wallet key-scan(hijacked Hadoop/YARN)Cryptojack miner fleet(infected hosts, GPU)Pool brute-force(SOCKS, dictionaries)Attacker wallets /redirected payouts

Figure 1. Three independent rackets, one shared control server and callback port.

How we found it

The host surfaced as a malicious open directory, worker scripts, mining binaries and a credential dictionary served straight out of an exposed HTTP root. We recovered and classified the contents automatically. Sensors place it on 2026-09-27.

1
Stage payloads
2
Hijack compute
3
Scan wallets
4
Mine + brute-force
5
Collect hits

1. Wallet key-scanning on stolen compute

The first racket is a distributed wallet-key scanning engine. A worker (qhmine_worker.sh, with Chinese comments noting it runs "inside hijacked YARN containers") pulls a native engine binary and a fuse16 filter set from the control server, then sweeps an assigned numeric range looking for funded wallets, bounding itself to eight threads per host and posting any hits back to a collector. The filter is almost certainly a precomputed set of funded addresses: the engine checks generated or harvested keys against it. The compute is not theirs, it runs inside hijacked Hadoop/YARN clusters, big, internet-exposed and rarely watched.

2. A GPU-aware cryptojacking fleet

The second racket is straightforward mining. deploy_node.sh is a textbook covert-miner installer: it hides in a randomly named /tmp/.scXXXX directory, pulls a fleet_lin.tgz bundle, launches a miner that exposes the familiar xmrig-style local APIs (:4068, :4069/2/summary), checks for a GPU with nvidia-smi, and persists through two crontab entries (@reboot and every eight minutes).

3. Mining-pool credential brute-forcing

The third racket targets the accounts of a cryptocurrency mining-pool platform (anonymised). Two workers, a bash/curl version (krworker.sh) and a long-running Python one (worker3.py), split a shared dictionary (mega_dict.txt) across a cluster by index, rotate user-agents and SOCKS proxies, fetch the login CSRF token and grind credentials for a list of target usernames, reporting hits to the control server on port 8899. Compromised pool accounts let the operator redirect other miners' payouts.

Attribution

Every worker carries Chinese-language comments and operational notes, placing a Chinese-speaking operator or crew behind the infrastructure. As always, language is an attribution lead, not a link to a named group. The three rackets share one control server and callback port, so this is one operation with three revenue streams, not three unrelated tools.

MITRE ATT&CK

TechniqueNameObserved via
T1496Resource Hijackingxmrig-style miner fleet; wallet-scan on YARN
T1110.001Brute Force: Password Guessingkrworker.sh / worker3.py vs a mining pool
T1053.003Scheduled Task/Job: Cron@reboot + */8 persistence
T1564.001Hide Artifacts: Hidden Files and Directories/tmp/.scXXXX miner dir
T1090.002Proxy: External Proxyrotating SOCKS proxies in the brute-forcer

Indicators

host    23.252.123.134 (WebNX, Inc., United States) [control server] seen    2026-09-27 to 2026-09-27 ports   8000 / 18095 (payload staging), 8899 (callback/cbmgr) files   qhmine_worker.sh, deploy_node.sh, krworker.sh, worker3.py, fleet_lin.tgz, fuse16.tgz host-ioc /tmp/.sc[0-9a-f]{4}/ miner dir; crontab @reboot + */8 * * * * persistence miner   local APIs on 127.0.0.1:4068 and :4069/2/summary

Defending against it

  • Lock down Hadoop/YARN: never expose the ResourceManager REST API to the internet; it is the most common entry point for this kind of cluster cryptojacking.
  • Hunt the persistence: look for /tmp/.sc* directories, crontab entries running a hidden binary every few minutes, and local miner APIs on 4068/4069.
  • Protect pool accounts: enforce MFA and rate-limit logins; this crew brute-forces them at scale from distributed workers.

Browse the running list of exposed C2 and malware infrastructure on live finds, or start free and hunt your own.

Get the next teardown + fresh IOCs

New attacker-infrastructure writeups and live indicators, straight to your inbox. No spam, unsubscribe anytime.

Hunt it yourself

Classify any IP, browse live attacker infrastructure, or deploy your own sensors. Free, no card.