Using the name “Los Zetas”, alluding to a Mexican criminal organization, a threat group has unleashed a new cryptocurrency BTC miner. It is hypothesized that, should this malware grow, it could make thousands of dollars within a period of one to two years. A compromised device downloads a malicious shell script which contains the commands to download the botnet client, create directories in which to copy the files, and execute the downloaded files. This allows the malware to communicate with an IRC server. The mining operation is concealed with a rootkit. This particular malware replaces the PS with a crafted version but filters out xmrig and emech processes and other keywords. Once all the files from the rootkit have been downloaded and installed, the malicious scripts will run and a connection to an IRC server is made.