Suspicious kswapd0 Masquerading Miner Process

PremiumReviewedSigma · High · v1
Product
linux
Category
process_creation
Author
HuntRule
Published
2026-10-09
Updated
2026-10-09

ATT&CK techniques

Defense Evasion → Impact
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

What it detects

This rule detects a process named kswapd0 executing from a user-writable path rather than existing only as a kernel thread which the Outlaw botnet uses to disguise its UPX-packed XMRig miner. Naming the miner after a legitimate kernel worker hides it from casual process inspection. Any on-disk kswapd0 binary in a home or tmp directory is anomalous.

Related detections9 linkedT1036.005 — drag to rearrange
Malicious Cryptominer Masquerading as Kubernetes pause Container
Suspicious Dero Miner Binaries nginx and cloud Execution
Suspicious msinfo32.exe Executed From ViPNet Update Directory
Malicious Desktop Window Manager Impersonation From Non-System Path via process_creation
Malicious Svchost Impersonation From Non-System Path via process_creation
Suspicious XMRig Cryptominer Execution with Pool URL by StaryDobry
Malicious RustyStealer Masquerading as AudioDriver in Windows Temp
Suspicious SteelFox Service Binary Launched by services.exe
Suspicious svchost Invocation with Non-Standard svcr Argument
Suspicious kswapd0 Masquerading Miner Process
Pivot detection · T1036.005 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.