Mal/Miner-C is designed to abuse resources of the infected machine to mine Monero (XMR) cryptocurrency. Malware leverages network-attached storage (NAS) devices as attack vector. The malware targeted various types of FTP servers, but Sophos experts noticed it mostly targeted Seagates Central NAS product. More than 1.7 million infections were observed in the first half of 2016, but they were associated to only 3,150 unique IP addresses because the malware copies itself to every folder on a compromised FTP server.”]
Source: https://securityaffairs.co/wordpress/51131/malware/malminer-c-mining-malware.html