TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

GreyNoise

PHP Cryptomining Campaign: October/November 2025

2025-11-04 · Read original ↗

ATT&CK techniques detected

6 predictions
T1190Exploit Public-Facing Application
87%
“core problem : old vulnerabilities don ’ t go away just because they ’ re old. organizations patch parts of their stack, but legacy frameworks and forgotten installs remain exploitable. that persistence creates a reliable attack surface. internet - facing servers are preferred mi…”
T1496Resource Hijacking
65%
“coin with minimal friction. there are no negotiations, no human - in - the - loop — just silent revenue flow. cloud cryptojacking activity rose roughly 20 % in 2025, showing that mining is now a commodity crime. the playbook is straightforward : scan, compromise, deploy a miner (…”
T1190Exploit Public-Facing Application
45%
“php cryptomining campaign : october / november 2025 what we ’ re seeing from august through october 2025, we observed ( greynoise visualizer ) a clear ramp - up in exploitation attempts against php and php - based frameworks as actors push to deploy cryptominers. the query below …”
T1496.001Compute Hijacking
40%
“coin with minimal friction. there are no negotiations, no human - in - the - loop — just silent revenue flow. cloud cryptojacking activity rose roughly 20 % in 2025, showing that mining is now a commodity crime. the playbook is straightforward : scan, compromise, deploy a miner (…”
T1496Resource Hijacking
40%
“php cryptomining campaign : october / november 2025 what we ’ re seeing from august through october 2025, we observed ( greynoise visualizer ) a clear ramp - up in exploitation attempts against php and php - based frameworks as actors push to deploy cryptominers. the query below …”
T1588.006Vulnerabilities
35%
“the operational pattern these campaigns use methodical internet scanning to find vulnerable php installs. exploitation is typically automated ; the same exploit will successfully target hundreds or thousands of identical stacks. cryptominer deployment follows a standard recipe an…”

Summary

From Aug–Oct 2025, GreyNoise observed a surge in exploitation attempts against PHP and PHP-based frameworks as attackers deployed cryptominers—driven by rising Bitcoin prices and higher mining payoffs.